Forum     

Go Back   Digit Technology Discussion Forum > Software > Open Source
Register FAQ Calendar Mark Forums Read

Open Source A place where you can talk to like-minded people about the fastest growing software movement today! Discuss anything and everything about Open Source software and Operating Systems.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 30-06-2006, 08:43 PM   #1 (permalink)
Right Off the Assembly Line
 
Join Date: Apr 2006
Posts: 4
Thumbs down sudo -s


any body can gain access to root by cmd "sudo -s" howto prevent this
ravix is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 30-06-2006, 08:58 PM   #2 (permalink)
Wise Old Owl
 
JGuru's Avatar
 
Join Date: Dec 2005
Location: Space-time continuum
Posts: 1,646
Default Re: sudo -s

That's a good question!! Either you delete the sudo executable, or move it to some
other place or rename it to a different name!! A good solution is move the executa
-ble 'sudo to your '/home/' and don't give the other users read-access or any other
access. 'Sudo' is located in the '/usr/bin' folder.
JGuru is offline  
Old 30-06-2006, 09:05 PM   #3 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Post Re: sudo -s

http://www.sudo.ws/pipermail/sudo-us...ay/001538.html

Quote:
In message <OF5E57D999.156B24E2-ON86256D24.00575E49-86256D24.005773A6 at cis.cat.c
om>
so spake "Nicholas C. Aganan" (Aganan_Nicholas_C):

> How will I disable sudo -s? I don't want this functionality to be given to
> my users.

"sudo -s" is just a shortcut for "sudo $SHELL". If your sudoers
file doesn't allow users t orun shells, they won't be able to do
"sudo -s" either.

- todd
Also refer:
http://forums.macnn.com/archive/index.php/t-18166.html
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org

Last edited by praka123; 30-06-2006 at 09:08 PM.
praka123 is offline  
Old 30-06-2006, 09:10 PM   #4 (permalink)
18 Till I Die............
 
Join Date: Jul 2004
Location: India, Mumbai, Marine Lines
Posts: 5,792
Default Re: sudo -s

Just make it non-executable for other users except you.
Code:
sudo chmod o-x /usr/bin/sudo
But if your account is compromised then well this trick won't help and neither will JGuru's.
mehulved is offline  
Old 01-07-2006, 12:41 AM   #5 (permalink)
Wise Old Owl
 
JGuru's Avatar
 
Join Date: Dec 2005
Location: Space-time continuum
Posts: 1,646
Default Re: sudo -s

If you want the best unbreakable protection you must include Biometrics. Including
a retina scan & a thumb print scanner. There are some Biometrics software
available in Linux. The researchers say that even finger-print can be spoofed by using
gelatin or other similar substances!! So the new Biometrics software looks for Sweat!!
Read more about it here:
http://news.zdnet.com/2100-1009_22-6003440.html

Last edited by JGuru; 01-07-2006 at 12:46 AM.
JGuru is offline  
Old 01-07-2006, 06:52 PM   #6 (permalink)
mera kutch nahi ho sakta
 
chesss's Avatar
 
Join Date: Oct 2005
Location: Delhi
Posts: 880
Default Re: sudo -s

Quote:
any body can gain access to root by cmd "sudo -s" howto prevent this
Wouldn't they have to know the pasword as well??
chesss is offline  
Old 01-07-2006, 08:13 PM   #7 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Talking Re: sudo -s

Quote:
Originally Posted by ravix
any body can gain access to root by cmd "sudo -s" howto prevent this
How dood?? My FC5 says "mediator is not in the sudoers file. This incident will be reported."
mediator is offline  
Old 02-07-2006, 12:40 AM   #8 (permalink)
18 Till I Die............
 
Join Date: Jul 2004
Location: India, Mumbai, Marine Lines
Posts: 5,792
Default Re: sudo -s

Well mediator just do this
Code:
su
visudo
And search for tutorials on net on how to add user/group to sudoers file.
I have left the ubuntu defualt
%admin ALL=(ALL) ALL.
Well you can customise it to your needs.
mehulved is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by topgear

Advertisement




All times are GMT +5.5. The time now is 08:49 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2