Tuesday, December 6, 2011

The echo command

The echo command echoes its arguments separated by blanks and terminated by a new line on the standard output.
Syntax:
              echo [arg] 
              echo[-n][arg]


The /user/bin/sh version understands the following C-like escape sequences:
 \b  backspace
 \c  print line without newline
\n   new--line
\r    carriage return
\t    tab
\v   vertical tab
\\    backslash
\n   where n is the 8 bit character whose ASCII code is the 1,2or 3 digit octal number representing that character.

The following option is available to /usr/bin/sh users only if /usr/ucb preceeds /usr/bin in the user's path.It is available to  /usr/csh users regardless of the PATH:
-n  Do  not add newline to the output

The echo command is useful for producing diagnostics in command files, for sending known data into a pipe, and for displaying the contents of environment variables.

The next command will be bc which is an arbitrary-precision arithmetic language in unix

Sunday, November 27, 2011

Choosing a Password and Password Files

Choosing a Password:


Passwords must be constructed to meet the following requirements:


  • Each password must have atleast PASSLENGTH characters as set in /etc/default/passwd file.PASSLENGTH must contain a minimum of 6 characters, but only the first 8 characters are significant.
  • Each  password must contain at least 2 alphabetic characters and atleast 1 numeric or special character.
  • Each password must differ from the user's login name and any reverse or circular shift of that login name. For comparison purposes, an upper case letter and its corresponding lower case letter are equivalent .
  • New passwords must differ from the old by atleast 3 characters.

Password Files:

The passwd  command uses the files /etc/shadow, /etc/passwd and /etc/oshadow.
The file /etc/passwd contains the following information for each user:
  • login name
  • dummy password
  • numerical user ID
  • numerical group ID
  • comment
  • initial working directory
  • program to be used as the shell
passwd is an ASCII file . Each field within each user's entry is separarted from the next by a colon. The comment field  can contain any information that the user desires. each user is separated from the next by a new-line. If the shell field is null, /usr/bin/sh is used.

This file has user login information and general read permission. It can therefore be used , to map numerical user ID's to names.
The password field consists of the character x.Password information is contained in the file /etc/shadow.




The next command will be the echo command.


Wednesday, November 23, 2011

The passwd command- continued

To recollect the syntax of the passwd command is:
              passwd[name]
              passwd[-l |-d ][-f][-n min][ -x max][-w warn] name
              passwd -s [-a]
              passwd -g [name]


The following options can be used only by a privileged user:

  • -l: Locks password entry for name.
  • -d: Deletes password for name. The login name will not be prompted for password.
  • -n: Sets minimum field for name.  The  min field contains the minimum number of days between password changes for  name.  If value of  min  >value of  max, the user may not change the password.Always use this option with the -x option, unless max is set to -1(ageing turned off ). In that case, min need not be set.
  • -x: Sets maximum field for name. The max  field  contains the number of days that the password is valid for name. The ageing of name  will be turned off if max is set to -1.
  • -w: Sets  warn  field for name. The warn  field contains the number of days the user will be warned before the password expires.
  • -a:  Shows password attributes for all entries. Use only with -s option ; name  must not be provided.
  • -f:  Forces the user to change password at the next login by expiring the password for name.
 Any user may use the -s option to show password attributes for one's own login name.
The format of the output will be:
name status mm/dd/yy min max warn

 Or, if password ageing information is absent,
name status

Super users may change any password; hence; passwd does not prompt privileged users for the old password. Privileged users are not forced to comply with password ageing and password construction requirements. A privileged user can create a null password by entering a carriage return in response to the prompt for a new password.

The passwd command exits with one of the following values:
0 SUCCESS
1 Permission denied
2 Invalid combination of options
3 Unexpected failure. Password file unchanged.
4 Unexpected failure .Password file is missing.
5 Password file(s) busy .Try again later
6 Invalid argument to option.


If root deletes a password for a user with the passwd -d command and password ageing is in effect for that user, the user will not be allowed to add a new password until the NULL password has been aged.This is true even if  the PASSREQ flag in /etc/login/default  is set to YES. This results in a  user without a password. It is recommended that the -f option be used with the  -d option so that the user is forced to change the password at the next login.


The next post will list the rules for choosing a password and the details of the files used by the passwd command.

Monday, November 21, 2011

The passwd command

The passwd command changes the password or lists attributes assosciated with the user's login name. Additionally, privileged users may use this command to install or change passwords and attributes assosciated with any login name.

Syntax:
              passwd[name]
              passwd[-l |-d ][-f][-n min][ -x max][-w warn] name
              passwd -s [-a]
              passwd -g [name]

  The behaviour of this command is extremely system-dependent.It asks you to enter your old  password, and if that is typed correctly,prompts you to enter your new password twice.The password may be chosen by a unix system or customized by the user. Some system administrators implement password aging which for security reasons forces the user to change the password after a certain period of usage.

Unix updates the corresponding files /etc/passwd  and /etc/shadow  for every change in password.
/etc/passwd  lists information about users.A user can read this file but not write into it. Each field of information is separated from the next by a ':' .An /etc/passwd file  dispalys login name, encrypted password,user ID, group Id, comment , default  working directory, default working shell.

There is another password file present in  /bin  directory called /bin/passwd . It is this file that actually gets executed when we change the password. Thus, /bin/passwd  is  an executable file which permits changing of password, whereas /etc/passwd  contains the information about each user.
 I shall discuss the options of the passwd command in the next post.

The uname command

The command uname prints the name of the current unix system.

Syntax:
uname[-amnprsv]
uname[-S system_name]
uname prints the current system name of the unix system to standard output.It is mainly useful to determine which system one is using.The options cause selected information returned by uname and/or sysinfo command to be printed:
  • -a : Print all information.
  • -m: Print the machine hardware name.
  • -n:  Print the node name(name by which the system is known to the communication  network)   .This is the default setting.
  • -p: Print the processor type of the current host.
  • -r: Print the operating system release.
  • -s:Print the name of the operating system.
  • -v: Print the version of the operating system.
 On your computer specifying a system name argument to the -S option may change the node name. The system name argument is restricted to SYS_NMLN  characters.SYS_NMLN is an implementation specific value defined in <sys/utsname.h>  file. Only the super-user is allowed to use this capability.

The next post will talk about the passwd command.

Tuesday, November 15, 2011

The tty command

The unix command tty displays the name of the terminal type.tty is the controling terminal interface.
The file /dev/tty is, in each process a synonym for the control terminal assosciated with the process group of that process. It can be used for programs that demand the name of a file for output, when typed output is desired .

Syntax:
            tty[-l][-s]
 The tty command prints the path name of the user terminal.
-l prints the synchronous line number to which the user's terminal is connected, if it is on an active
    synchronous line.
-s inhibits the printing of the terminal path name, allowing one to just test the exit code.
    The exit codes are as follows:
 2 if invalid options were specified
 0 if standard input is a terminal.
 1 otherwise

The error message  not an active synchronous line,  appears if the standard input is not a synchronous terminal and -1 is specified.

The error message  not a tty, appears if the standard input is not a terminal and -s is not specified.

The who command -continued

The options assosciated with the who command are as follows:

  • -u:    This option lists only those users who are currently logged in .The name  is the user's login name. The line is the name of the line as found in the directory /dev. The  time is the time that the user logged in. The  idle column contains the number of hours and minute  since  activity last occurred on that particular line. A dot(.) indicates that the terminal has seen activity in the last minute and is therefore 'current'. I f more than 24 hours have lapsed or the line has not been used since boot time, the entry is marked old. This field is useful to find out whether a person is currently working at the terminal line or not. The pid is the process-ID of the user's shell. The  comment is the comment field assosciated with this line as found in  /sbin/inittab  file. This can contain information about where the terminal is located, the telephone number of the data set, type of terminal if hard-wired and so on.
  • -T:     This option is same as the -s option except that the state  of the terminal line is printed.The state  describes whether  someone else can write to that terminal. A '+' appears if the terminal is writeable by anyone, else a '-' sign appears.  root  can write to all lines whether a '+' appears or a '-'.If a bad line is encountered a question mark(?) is printed.
  • -l:       This option lists only those lines on which the system is waiting for someone  to login.The  name is LOGIN  in such cases. Other fields are same except that the  state  field does not exist.
  • -H:     This option will print column headings above the  regular output.
  • -q:      This is a 'quick who' listing only the names and numbers of the users currently logged in. When this option is used all other options are ignored.
  • -p:      This option lists any process that is currently active and has previously been spawned by init. The  name is the name of the program executed by init   as found in /sbin/inittab file. The state,line  and idle  fields have no meaning .The  comment  field shows the  id  field from the   /sbin/inittab  file that generated this process.
  • -d:       This option displays all processes that have expired and not been regenerated by init.The exit field appears for dead processes and  contains the termination and exit values, as returned by the wait command. This can be useful in determining why a process terminated.
  • -b:        This option indicates the time and date of the last reboot.
  • -r:         This option indicates the current run level of the init process.It also displays the process termination status ,process-ID and process exit status under the idle,pid and the comment  headings respectively.
  • -t:          This option indicates the last change to the system clock via the date  commnad , by root. 
  • -a:         This option processes /var/adm/utmp  file or the named file with all options turned on.
  • -s:         This option is the default and lists only the  name, line and time fields respectively.
  • -nx:       This optin takes a numeric argument, x , which specifies the number of users to display per line. x must be at least 1. The -n option must be used with -q.

After a shutdown to the single user state, who returns a prompt.The reason is that since /var/adm/utmp file is updated at login time and there is no login in single user state, who cannot report accurately on this state.  who am i  however returns the correct information.
The who command uses the files / var/adm/utmp, / var/adm/wtmp  and /sbin/inittab.

 The next post would be about tty command.