republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Forum FAQ ·Attitude Adjustment ·Linux docs ·DistroWatch ·OPLM
AuthorAll Replies

BosstonesOwn

join:2002-12-15
Everett, MA

reply to graysonf

Re: Odd winbind behavior CentOS release 5.7 (Final)

looked into this, still allows them to get a root shell.

Ill keep poking around , thanks.


graysonf
Premium,MVM
join:1999-07-16
Fort Lauderdale, FL

I think that members of the wheel group get an unrestricted sudo and can su to root or otherwise spawn a root shell.

You probably should remove those users from the wheel group and only allow them a restricted sudo granting them only the commands they actually need to run with root privileges.


BosstonesOwn

join:2002-12-15
Everett, MA

just ran tests with that worked ok and had some builds fail. Problem is we were told this has to now go to workstations also so now i need to find a solution that allows them to have root to local boxes as well via sudo.
--
"It's always funny until someone gets hurt......and then it's absolutely friggin' hysterical!"


BosstonesOwn

join:2002-12-15
Everett, MA

found a weird way to stop it for now on the servers. Workstations may be more difficult.

Basically added individuals to wheel then the whole group in sudoer file and locked certain commands for just sudo and bash

but left the domain admin accounts free to run it all.

Cmnd_Alias NSHELLS = /bin/sh,/bin/bash
Cmnd_Alias NSU = /bin/su
%wheel ALL=(ALL) !NSHELLS, !NSU
%dev_kernel ALL= ALL, !NSHELLS, !NSU
%dev_drivers ALL= ALL, !NSHELLS, !NSU
--
"It's always funny until someone gets hurt......and then it's absolutely friggin' hysterical!"


Tuesday, 18-Jun 03:25:21 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics