Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: root group in solaris : Tools |
|---|---|
| Date: | Fri, 22 Sep 2006 14:15:18 -0600 (MDT) |
Mike Kuriger writes:
sodo provides logging, and commands suck as /bin/sh etc can be put into a group in /etc/sudoers and forbidden. then add users to the wheel group who need sudo access. of course there are ways around the forbidden things. you can be specific with which commands they can run so that they don't write shell scripts and run them with sudo to bypass the forbidden binaries.
Cmnd_Alias SHELLS = /sbin/sh,\
/bin/sh,/bin/csh,/bin/tcsh,/bin/ksh,\
/usr/bin/sh,/usr/bin/csh,/usr/bin/tcsh,/usr/bin/ksh
Cmnd_Alias FORBIDDEN = /bin/passwd root,/bin/su,/sbin/su
%wheel ALL = (ALL) ALL,!SHELLS,!FORBIDDEN
Doesn't help. If you allow the user to sudo any program that allows them to shell out (i.e. vi, more) they can get a root shell. If you need to stop people with sudo access from getting a root shell you need to have only allow lists, not deny lists. And, obviously, you need to be very careful about what programs you allow them. I did once hack up both vi and more so users couldn't shell out, but unfortunately that code is long gone. -- Michael T Pins | "It is not knowable how long that conflict mtpins@nndev.org | (Iraq) would last. It could last, you know, keeper of the nn sources | six days, six weeks. I doubt six months." ftp://ftp.nndev.org/pub | - Donald Rumsfeld, Feb 7, 2003
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: root group in solaris : Tools, Tonnerre Lombard |
|---|---|
| Next by Date: | Re: root group in solaris, Tonnerre Lombard |
| Previous by Thread: | Re: root group in solaris : Tools, Tonnerre Lombard |
| Next by Thread: | Re: root group in solaris : Tools, Casper . Dik |
| Indexes: | [Date] [Thread] [Top] [All Lists] |