xref: /freebsd/contrib/sendmail/smrsh/smrsh.8 (revision 6e8394b8baa7d5d9153ab90de6824bcd19b3b4e1)
Copyright (c) 1998 Sendmail, Inc. All rights reserved.
Copyright (c) 1993 Eric P. Allman. All rights reserved.
Copyright (c) 1993
The Regents of the University of California. All rights reserved.

By using this file, you agree to the terms and conditions set
forth in the LICENSE file which can be found at the top level of
the sendmail distribution.


@(#)smrsh.8 8.7 (Berkeley) 5/19/1998

SMRSH 8 11/02/93
NAME
smrsh - restricted shell for sendmail
SYNOPSIS
smrsh -c command
DESCRIPTION
The smrsh program is intended as a replacement for sh for use in the ``prog'' mailer in sendmail (8) configuration files. It sharply limits the commands that can be run using the ``|program'' syntax of sendmail in order to improve the over all security of your system. Briefly, even if a ``bad guy'' can get sendmail to run a program without going through an alias or forward file, smrsh limits the set of programs that he or she can execute.

Briefly, smrsh limits programs to be in the directory /usr/libexec/sm.bin, allowing the system administrator to choose the set of acceptable commands. It also rejects any commands with the characters `\`', `<', `>', `|', `;', `&', `$', `(', `)', `\er' (carriage return), or `\en' (newline) on the command line to prevent ``end run'' attacks.

Initial pathnames on programs are stripped, so forwarding to ``/usr/bin/vacation'', ``/home/server/mydir/bin/vacation'', and ``vacation'' all actually forward to ``/usr/libexec/sm.bin/vacation''.

System administrators should be conservative about populating /usr/libexec/sm.bin. Reasonable additions are vacation (1), procmail (1), and the like. No matter how brow-beaten you may be, never include any shell or shell-like program (such as perl (1)) in the sm.bin directory. Note that this does not restrict the use of shell or perl scripts in the sm.bin directory (using the ``#!'' syntax); it simply disallows execution of arbitrary programs.

COMPILATION
Compilation should be trivial on most systems. You may need to use -DPATH=\e"path\e" to adjust the default search path (defaults to ``/bin:/usr/bin'') and/or -DCMDBIN=\e"dir\e" to change the default program directory (defaults to ``/usr/libexec/sm.bin'').
FILES
/usr/libexec/sm.bin - directory for restricted programs
SEE ALSO
sendmail(8)