Re: root group in solaris : Tools
Tonnerre Lombard <[email protected]> Wed, 27 Sep 2006 07:40:43 +0200
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Organization | SyGroup GmbH |
| Message-ID | <[email protected]> |
--=-eJXz76W09gwz9uiOtx8c Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Salut, On Tue, 2006-09-26 at 11:09 -0700, Mike Kuriger wrote: > true, but sudo is for administrators. if a regular user needs root > access for anything, it's always just one or 2 commands which we make a > rule for. But true, it's very easy to get a root shell with sudo What I meant to say is, if you give an user root privileges and the ability to choose in any way what to run, you can't restrict him anymore. (Even though the restriction seems to be a central point in this thread.) Tonnerre --=20 SyGroup GmbH Tonnerre Lombard Loesungen mit System Tel:+41 61 333 80 33 Roeschenzerstrasse 9 Fax:+41 61 383 14 67 4153 Reinach BL Web:www.sygroup.ch [email protected] --=-eJXz76W09gwz9uiOtx8c Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (NetBSD) iQIVAwUARRoO2u1mMGan/TnWAQL7pQ//QULL+uiWl8rYc8GXcf9rjuWvMdaL9dcT g2eCUJKGYI8oBf9OPxwh0+5091SAss5YhsVjVck6uZifTlXnhdUSa9KpY3jkybmo ZenjqdB9u9vH0xA68EXtyS7YuUAJ+RcwG8NCygvG017YxaEz09nnMuT0ZKamTeNp zX4PTeuB0vcwPj9m+2lX/Pu9i/JPsezsuCABgTyaY7e/ct0XUSZOihZhWSUecJnR nYNSj8fHB1cGgucC7VRbGo1kTU13kZeEgX1W0onY7Bkq57DhTp6T8CpItKzIJ1D2 MmfRbRRmBIKQ+FCOBr2N2FzGYsQ8IHttiCngsM6GS1DNL/1l6tyFGDFQIaMfhsVK XnvyAJbFxcLVyqhsusG9B7cdptvZ7AHDsqkghZHCra1qJJ9C2rhUQ56WiY+AAdhY Iln/u+bxny9ghiEr/q3QrVpH7xjqnLDMtTGdmNMcp7J7dEgsUK7AgznzFjjqDv2h g5WNr3N1I8YihOWFkzfw0ZT/UBxSY9mON6VEmLvVvQTTOckHULssOyK/udXweFqr RUPVcFYGB2aB/kdY31N+GSgaOarEWec/psVfjKLk94D1ruMaX3gGr8D3z7RvqhJa pzqLqpXXftJ44jYTLH5kJ5U8ktspe7YbqHa4XqWa1qcrFqD4APqFy72RbAAPKflM eV3iWzPLR0g= =+9yh -----END PGP SIGNATURE----- --=-eJXz76W09gwz9uiOtx8c--