<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[刘新修]]></title> 
<link>http://liuxinxiu.com:80/index.php</link> 
<description><![CDATA[刘新修的个人博客 (Liuxinxiu'S Blog)]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[刘新修]]></copyright>
<item>
<link>http://liuxinxiu.com:80/s//</link>
<title><![CDATA[/bin/false和/sbin/nologin的区别]]></title> 
<author>刘新修 &lt;admin@yourname.com&gt;</author>
<category><![CDATA[Linux/Unix]]></category>
<pubDate>Thu, 11 May 2017 02:20:55 +0000</pubDate> 
<guid>http://liuxinxiu.com:80/s//</guid> 
<description>
<![CDATA[ 
	<div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">/bin/false和/sbin/nologin的区别</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">1 区别&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">/bin/false是最严格的禁止login选项，一切服务都不能用。&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">/sbin/nologin只是不允许login<a href="http://www.2cto.com/os/" target="_blank" class="keylink" style="color: rgb(51, 51, 51); text-decoration: none;">系统</a>&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">其中树莓派的/sbin/nologin文件在/usr/sbin/nologin&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">小技巧：&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">查看 /etc/passwd文件，能看到各用户使用的shell&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">2.1 nologin&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">当用户配置成/sbin/nologin时，如果再使用该用户ssh到linux操作系统，会提示&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">This account is currently not available.&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">如果在树莓派下，配置错误，误将/usr/sbin/nologin配置成/sbin/nologin，SSH时会提示&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">root@r<a href="http://www.2cto.com/kf/web/asp/" target="_blank" class="keylink" style="color: rgb(51, 51, 51); text-decoration: none;">asp</a>berrypi:/home# useradd -s /sbin/nologin piaohailin&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">root@raspberrypi:/home# su piaohailin&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">Cannot execute /sbin/nologin: No such file or directory&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">2.2 false&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">当用户配置成/bin/false时，ssh之后显示如下&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">root@raspberrypi:/home# useradd -s /bin/false piaohailin&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">root@raspberrypi:/home# su piaohailin&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">root@raspberrypi:/home# whoami&nbsp;</div><div style="border-width: 0px; padding: 0px; margin: 0px; list-style: none; color: rgb(51, 51, 51); font-family: 宋体; background-color: rgb(249, 249, 249);">root&nbsp;</div><p><span style="background-color: rgb(249, 249, 249); color: rgb(51, 51, 51); font-family: 宋体;">不会有任何提示，用户切换不过去</span>&nbsp;</p>
]]>
</description>
</item><item>
<link>http://liuxinxiu.com:80/s//#blogcomment</link>
<title><![CDATA[[评论] /bin/false和/sbin/nologin的区别]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://liuxinxiu.com:80/s//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>