From d3c45eaee122516d0620bb523d09661a8e6f71ca Mon Sep 17 00:00:00 2001 From: acinonyx Date: Wed, 2 Feb 2011 18:50:50 +0000 Subject: [package] busybox: Disable telnet if an SSH public key for root exists (#8760) git-svn-id: svn://svn.openwrt.org/openwrt/trunk@25317 3c298f89-4303-0410-b956-a3cf2f4a3e73 --- package/busybox/files/telnet | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'package') diff --git a/package/busybox/files/telnet b/package/busybox/files/telnet index b8823379b9..a1e17275a3 100755 --- a/package/busybox/files/telnet +++ b/package/busybox/files/telnet @@ -10,8 +10,14 @@ has_root_pwd() { test -n "${pwd#!}" } +has_ssh_pubkey() { + ( test -x /usr/sbin/dropbear && grep -qs "^ssh-" /etc/dropbear/authorized_keys ) || \ + ( test -x /usr/sbin/sshd && grep -qs "^ssh-" /root/.ssh/authorized_keys ) +} + start() { - if ( ! has_root_pwd /etc/passwd && ! has_root_pwd /etc/shadow ) || \ + if ( ! has_ssh_pubkey && \ + ! has_root_pwd /etc/passwd && ! has_root_pwd /etc/shadow ) || \ ( [ ! -x /usr/sbin/dropbear ] && [ ! -x /usr/sbin/sshd ] ); then telnetd -l /bin/login.sh -- cgit v1.2.3