Re: sudo and command line expansion

From: Ali-Reza Anghaie (ali@packetknife.com)
Date: 12/18/02


From: Ali-Reza Anghaie <ali@packetknife.com>
Date: Tue, 17 Dec 2002 19:59:03 -0500

Kent Smith wrote:
> Furthermore, IT WOULD BE LOGGED, so you could see if anyone it trying
> this on your machine. You *are* logging sudo aren't you?
>
> Security isn't worth much without reasonable monitoring.

Just another note on what I'm hoping would be obvious but I've seen people
do wrong... don't allow sudo access to another user shell unless you really
want a person to be root. Don't give sudo access to something that can make
shells calls outside of itself as well (i.e. :!<command> in vi). Etc.

Cheers, -Ali

-- 
OpenPGP Key: 030E44E6
--
Affero Fund: http://svcs.affero.net/rm.php?r=packetknife&p=default]</a>
<a href="attachment.html">[ attachment ]</a>
</ul>
<They say such nice things about people at their funerals that it
--
They say such nice things about people at their funerals that it
makes me sad that I'm going to miss mine by just a few days.
-- Garrison Keilor


Relevant Pages

  • Re: User accounts not accessible
    ... which user currently has sudo access? ... best bet is to 'sudo visudo' and edit the sudo rights for the user you ... Frustra laborant quotquot se calculationibus fatigant pro inventione ... Mark Haney ...
    (Ubuntu)
  • Re: configuring sudo access for some users
    ... I want to configure sudo access for some users on my system. ... You don't want them running any shells (so no sudo -i) unless you have them thoroughly constrained with selinux. ... they are not able to become root user when they issue "su -". ... Ankush Grover ...
    (Fedora)
  • Re: [Media] 8.04 Servers - Wikipedia & Sudoers, oh my!
    ... But all that it describes is not a language. ... Host is the machine sudo is running on. ... administrators that have full sudo access and a dozen accountants with limited ... rshdoes not allocate a tty. ...
    (Ubuntu)
  • Re: User accounts not accessible
    ... could some one help as i want to delete the user admin1 and give the ... which user currently has sudo access? ... best bet is to 'sudo visudo' and edit the sudo rights for the user you ... i can access sudo with both the users but somehow i cant manage the format ...
    (Ubuntu)
  • Re: [OT] Debian mailinglists [was: RE: Debian or Ubuntu?]
    ... Ubuntu that the first user set up on the system has sudo access. ...
    (Ubuntu)