User & Group Management
Stop letting your system accounts log in and ruin your day
🧩 The Challenge
Setting up a service account for a web app and realized too late that you left it with a valid login shell. It is a massive security hole that takes one disgruntled developer or a leaked key to turn into a full-blown root compromise.
💡 The Fix
Flip that shell to nologin or false so nobody can actually spawn a process as that user. It keeps the account functional for your daemon but kills the interactive session immediately.
usermod -s /usr/sbin/nologin your_service_user_name
⚙️ Why It Works
By pointing the user’s shell to that specific binary, the system intercepts any attempt to start an interactive session and bounces it back with a polite message. Changing it to /bin/false is even stricter since it just exits immediately without telling the user a single thing.
🚀 Pro-Tip: Always audit your /etc/passwd file for any account with a UID lower than 1000 that still has /bin/bash sitting there.
Linux Tips & Tricks | © ngelinux.com | 9/29/2026
