Re: root group in solaris : Tools

Tonnerre Lombard <[email protected]> Wed, 27 Sep 2006 07:40:43 +0200
Newsgroups gmane.comp.security.sun
Organization SyGroup GmbH
Message-ID <[email protected]>
--=-eJXz76W09gwz9uiOtx8c
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Salut,

On Tue, 2006-09-26 at 11:09 -0700, Mike Kuriger wrote:
> true,  but sudo is for administrators.  if a regular user needs root
> access for anything, it's always just one or 2 commands which we make a
> rule for.  But true, it's very easy to get a root shell with sudo

What I meant to say is, if you give an user root privileges and the
ability to choose in any way what to run, you can't restrict him
anymore. (Even though the restriction seems to be a central point in
this thread.)

				Tonnerre
--=20
SyGroup GmbH
Tonnerre Lombard

Loesungen mit System
Tel:+41 61 333 80 33    Roeschenzerstrasse 9
Fax:+41 61 383 14 67    4153 Reinach BL
Web:www.sygroup.ch      [email protected]

--=-eJXz76W09gwz9uiOtx8c
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (NetBSD)

iQIVAwUARRoO2u1mMGan/TnWAQL7pQ//QULL+uiWl8rYc8GXcf9rjuWvMdaL9dcT
g2eCUJKGYI8oBf9OPxwh0+5091SAss5YhsVjVck6uZifTlXnhdUSa9KpY3jkybmo
ZenjqdB9u9vH0xA68EXtyS7YuUAJ+RcwG8NCygvG017YxaEz09nnMuT0ZKamTeNp
zX4PTeuB0vcwPj9m+2lX/Pu9i/JPsezsuCABgTyaY7e/ct0XUSZOihZhWSUecJnR
nYNSj8fHB1cGgucC7VRbGo1kTU13kZeEgX1W0onY7Bkq57DhTp6T8CpItKzIJ1D2
MmfRbRRmBIKQ+FCOBr2N2FzGYsQ8IHttiCngsM6GS1DNL/1l6tyFGDFQIaMfhsVK
XnvyAJbFxcLVyqhsusG9B7cdptvZ7AHDsqkghZHCra1qJJ9C2rhUQ56WiY+AAdhY
Iln/u+bxny9ghiEr/q3QrVpH7xjqnLDMtTGdmNMcp7J7dEgsUK7AgznzFjjqDv2h
g5WNr3N1I8YihOWFkzfw0ZT/UBxSY9mON6VEmLvVvQTTOckHULssOyK/udXweFqr
RUPVcFYGB2aB/kdY31N+GSgaOarEWec/psVfjKLk94D1ruMaX3gGr8D3z7RvqhJa
pzqLqpXXftJ44jYTLH5kJ5U8ktspe7YbqHa4XqWa1qcrFqD4APqFy72RbAAPKflM
eV3iWzPLR0g=
=+9yh
-----END PGP SIGNATURE-----

--=-eJXz76W09gwz9uiOtx8c--