
242
|
Chapter 9, Administration and Automation
#80 Protect Yourself from Windows Applications
HACK
This hack requires several steps:
1. Install
sudo, if you don’t already have it installed.
2. Create a user and a group named
jail.
3. Install Wine or CrossOver Office as the user
jail in the /home/jail
directory.
4. Create the /home/jail/Documents directory, and give everyone read/write
access to the directory.
5. Set up the sudoers file to enable you to run certain applications as the
jail user.
6. Install a special script in /usr/local/bin that automatically uses Microsoft
Word, running in the jailed environment, to open any Word document
in read-only mode.
Get Your Safe Environment Set Up
Create both a user and a group named jail. Make the jail user a member
of the
jail group, but do not add this user to any other groups. You want
the
jail user to have as few privileges as possible. Your Linux distribution
probably includes a graphical application to manage users and groups. If
you prefer to use the command line, one way to create this user is to log in
as root and issue the following commands:
# groupadd jail
# useradd jail -d /home/jail -m -g jail -s /bin/bash
# passwd jail
New UNIX password: <password>
Retype new UNIX password: <password>
passwd: password updated successfully
Though you are providing a password, you will configure
sudo such that users do not need to enter the password to use
the
jail account to ...