Creating & deleting system service agent accounts on Mac OS X
Inspired by: Description and guidelines on creating system service agent accounts on Mac OS X (Tiger) and HiddenAdminCreate
Use at your own risk!
1. create a system service agent account
2. delete a system service agent account
Use at your own risk!
1. create a system service agent account
#!/bin/bash if [[ "$(/usr/bin/whoami)" != "root" ]]; then printf '\nMust be run as root!\n\n'; exit 1; fi OPATH=$PATH export PATH=/usr/bin:/usr/sbin:/bin:/sbin OIFS=$IFS export IFS=$' \t\n' printf '\n\e[1mYou are going to create a system service agent account!\e[m\n\n' declare sudo=/usr/bin/sudo dscl=/usr/bin/dscl # first name printf "\e[1mEnter first name\e[m: " read fn # no spaces in names if [[ -z "$(printf -- "$fn" | /usr/bin/grep -Eo "^[^[:space:]]+$")" ]]; then printf '\nUse a name without spaces! \nPlease, try again!\n\n' exit 1 fi # name must not begin with a number if [[ -n "$(printf -- "$fn" | /usr/bin/grep -E "^[[:digit:]]")" ]]; then printf '\nName must not begin with a number! \nPlease, try again!\n\n' exit 1 fi # make sure the user name is unique new_user="$(/usr/bin/dscl . -search /Users name "$fn" 2>/dev/null)" if [[ -z "$new_user" ]]; then new_user="$fn" else printf "\nUser name already exists: $fn \nPlease, modify your name and try it again\x21\n\n" exit 1 fi # make sure the agent's primary group name is unique # note: the agent's primary group name is also based on the first name! new_group="$(/usr/bin/dscl . -search /Groups name "$fn")" if [[ -z "$new_group" ]]; then new_group="$fn" else printf "\nThe agent's primary group name already exists: $fn\x21 \nPlease, try again\x21\n\n" exit 1 fi # last name printf '\nNote: The \e[1mlast name\e[m is \e[1moptional\e[m and defaults to "agent" if you just press!\n ' printf "\e[1mEnter last name\e[m: " read ln if [[ -z "$ln" ]]; then ln="agent"; fi # no spaces in names if [[ -z "$(printf -- "$ln" | /usr/bin/grep -Eo "^[^[:space:]]+$")" ]]; then printf '\nUse a name without spaces! \nPlease, try again!\n\n' exit 1 fi # name must not begin with a number if [[ -n "$(printf -- "$ln" | /usr/bin/grep -E "^[[:digit:]]")" ]]; then printf '\nName must not begin with a number! \nPlease, try again!\n\n' exit 1 fi # user shell printf '\nNote: The \e[1muser shell\e[m is \e[1moptional\e[m and defaults to "/usr/bin/false" if you just press!\n' printf "\e[1mEnter user shell\e[m: " read sh if [[ -z "$sh" ]]; then sh="/usr/bin/false"; fi # test if user shell exists if [[ ! -e "$sh" ]]; then printf "\nUser shell does not exist: $sh\n\n" exit 1 fi # home directory printf '\nNote: The \e[1mhome directory\e[m is \e[1moptional\e[m and defaults to "/private/var/empty" if you just press!\n' printf "\e[1mEnter home directory\e[m: " read hd if [[ -z "$hd" ]]; then hd="/private/var/empty" elif [[ "${hd:0:1}" != '/' ]]; then printf '\nThe home directory path does not begin with a slash "/".\nPlease, try again!\n\n' exit 1 elif [[ -e "$hd" ]]; then printf "\nHome directory already exists: $hd \nPlease, try again\x21\n\n" exit 1 fi hd=${hd%/} # remove a trailing slash character "/" if necessary # get unique id numbers (uid, gid) unset -v new_uid new_gid i declare -i new_uid=0 new_gid=0 i=100 while [[ $i -lt 500 ]]; do # try to get $new_uid and $new_gid between 100 and 500 i=$[i+1] if [[ -z "$(/usr/bin/dscl . -search /Users uid $i)" ]] && [[ -z "$(/usr/bin/dscl . -search /Groups gid $i)" ]]; then new_uid=$i new_gid=$i break fi done if [[ $new_uid -eq 0 ]] || [[ $new_gid -eq 0 ]]; then # get $new_uid and $new_gid greater than 500 i=500 idvar=0 while [[ $idvar -eq 0 ]]; do i=$[i+1] if [[ -z "$(/usr/bin/dscl . -search /Users uid $i)" ]] && [[ -z "$(/usr/bin/dscl . -search /Groups gid $i)" ]]; then new_uid=$i new_gid=$i idvar=1 #break fi done fi if [[ $new_uid -eq 0 ]] || [[ $new_gid -eq 0 ]]; then printf 'Getting unique id numbers (uid, gid) failed!\n'; exit 1; fi # check once again ... if [[ $new_uid -eq $new_gid ]] && [[ "$new_user" == "$fn" ]] && [[ "$new_group" == "$fn" ]]; then # create home directory if [[ "$hd" != "/private/var/empty" ]]; then $sudo /bin/mkdir -p "$hd" fi # create the agent's primary group $sudo /usr/sbin/dseditgroup -o create -r "$fn $ln" -i $new_gid "$new_group" $sudo $dscl . -append "/Groups/$new_group" passwd "*" # create the system service agent $sudo $dscl . -create /Users/$new_user $sudo $dscl . -append /Users/$new_user RealName "$fn $ln" $sudo $dscl . -append /Users/$new_user uid $new_uid $sudo $dscl . -append /Users/$new_user gid $new_gid $sudo $dscl . -append /Users/$new_user shell "$sh" $sudo $dscl . -append /Users/$new_user home "$hd" $sudo $dscl . -create /Users/$new_user passwd "*" $sudo $dscl . -append "/Groups/$new_group" GroupMembership "$new_user" # add new agent to the agent's primary group #$sudo /usr/sbin/dseditgroup -o edit -a "$new_group" -t user "$new_user" else printf "\nConfiguration of system service agent account: $fn failed\x21 \nPlease, try again\x21\n\n" exit 1 fi # create further subdirectories if necessary #if [[ "$hd" != "/private/var/empty" ]]; then # #if [[ "$new_user" == "clamavadmin" ]]; then # # additional subdirectories for the clamavadmin system service agent account # $sudo /bin/mkdir -p "$hd"/log # $sudo /usr/bin/touch "$hd"/log/clamd.log # $sudo /bin/mkdir -p "$hd"/tmp # $sudo /bin/mkdir -p "$hd"/share/clamav # $sudo /usr/sbin/chown -R $new_user:$new_user "$hd" # $sudo /bin/chmod -R 750 "$hd" #fi # #fi printf "\nSystem service agent account: \e[1m$fn\e[m successfully created\x21\n\n" export IFS=$OIFS export PATH=$OPATH exit 0 #--------------------------- # test dscl . list /Users dscl . -read /Users/dscl . list /Groups dscl . -read /Groups/ dscl . list /Groups GroupMembership
2. delete a system service agent account
#!/bin/bash if [[ "$(/usr/bin/whoami)" != "root" ]]; then printf '\nMust be run as root!\n\n'; exit 1; fi OPATH=$PATH export PATH=/usr/bin:/usr/sbin:/bin:/sbin OIFS=$IFS export IFS=$' \t\n' declare sudo=/usr/bin/sudo printf "\n\e[1mDelete system service agent account\e[m: " read agent if [[ -z "$agent" ]]; then printf '\nNo name for system service agent specified! Please, try again!\n\n'; exit 1; fi # make sure the agent exists agenttest="$(/usr/bin/dscl . -search /Users name "$agent")" if [[ -z "$agenttest" ]]; then printf "\nThe system service agent does not exist: $agent\n\n"; exit 1; fi # find the agent's home directory home=$(/usr/bin/dscl . -read /Users/$agent home | awk -F ': ' '{ print $NF; }' ) # get the agent's group memberships groups_of_agent="$(/usr/bin/id -Gn $agent)" # delete the agent's group memberships if [[ $? -eq 0 ]] && [[ -n "$(/usr/bin/dscl . -search /Groups GroupMembership "$agent")" ]]; then for group in $groups_of_agent; do $sudo /usr/bin/dscl . -delete "/Groups/$group" GroupMembership "$agent" #$sudo /usr/sbin/dseditgroup -o edit -d "$agent" -t user "$group" done fi # delete the agent's primary group if [[ -n "$(/usr/bin/dscl . -search /Groups name "$agent")" ]]; then $sudo /usr/sbin/dseditgroup -o delete "$agent" fi # if the agent's primary group has not been deleted ... if [[ -n "$(/usr/bin/dscl . -search /Groups name "$agent")" ]]; then printf " \e[1mWarning\e[m: The group memberships of the system service agent \e[1m$agent\e[m have been deleted\x21 groups_of_agent: $groups_of_agent The agent's primary group \e[1m$agent\e[m, however, has not been deleted\x21 Please, try again\x21 Exiting ...\n " exit 1 fi # find the GeneratedUID of the agent and remove the password hash file # from /private/var/db/shadow/hash/# sudo ls -a /private/var/db/shadow/hash # sudo ls -l /private/var/db/shadow/hash/ guid="$(/usr/bin/dscl . -read "/Users/$agent" GeneratedUID | /usr/bin/awk '{print $NF;}')" if [[ -f "/private/var/db/shadow/hash/$guid" ]]; then $sudo /bin/rm -f /private/var/db/shadow/hash/$guid fi # delete the agent $sudo /usr/bin/dscl . -delete "/Users/$agent" # make a backup if [[ -d "$home" ]] && [[ "$home" != "/private/var/empty" ]]; then $sudo /usr/bin/ditto -rsrc -c -k "$home" "${home}-archive-$(/bin/date).zip" fi # remove the agent's home directory if [[ -d "$home" ]] && [[ "$home" != "/private/var/empty" ]]; then $sudo /bin/rm -rf "$home" fi printf "\nSystem service agent account: \e[1m$agent\e[m successfully deleted\x21\n\n" export IFS=$OIFS export PATH=$OPATH exit 0