Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #210087 > unrolled thread

Giving remaja (teens) group full administrator privileges through sudo - dangerous?

Started byBagas Sanjaya <bagasdotme@gmail.com>
First post2019-06-19 06:30 +0200
Last post2019-07-02 14:50 +0200
Articles 20 on this page of 61 — 24 participants

Back to article view | Back to linux.debian.user


Contents

  Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-19 06:30 +0200
    Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? john doe <johndoe65534@mail.com> - 2019-06-19 08:00 +0200
    Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-19 08:10 +0200
    Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Carl <carlf@panix.com> - 2019-06-19 13:40 +0200
      Re: Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 07:20 +0200
        Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Richard Hector <richard@walnut.gen.nz> - 2019-06-20 07:40 +0200
          Re: Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 09:20 +0200
            Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Curt <curty@free.fr> - 2019-06-20 11:10 +0200
            Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? rhkramer@gmail.com - 2019-06-20 14:10 +0200
        Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Carl <carlf@panix.com> - 2019-06-20 13:00 +0200
          Re: Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 14:50 +0200
            Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-20 18:40 +0200
              Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Carl Fink <carlf@panix.com> - 2019-06-21 21:50 +0200
                Re: Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-22 01:00 +0200
                  Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 04:30 +0200
                    Re: Re: Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-22 10:40 +0200
                      Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? rhkramer@gmail.com - 2019-06-22 12:30 +0200
                        Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 17:30 +0200
                          Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Brad Rogers <brad@fineby.me.uk> - 2019-06-22 18:20 +0200
                            Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 18:30 +0200
                              Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Curt <curty@free.fr> - 2019-06-22 18:50 +0200
                    Re: Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-22 10:50 +0200
                    Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 16:20 +0200
                  Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Carl <carlf@panix.com> - 2019-06-22 14:20 +0200
                Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 02:40 +0200
                  Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Curt <curty@free.fr> - 2019-06-22 10:10 +0200
                    Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-22 10:50 +0200
                    Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-22 10:50 +0200
                      Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 11:50 +0200
                        Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-22 12:30 +0200
                          Re: Off topic: remaja (teens) <tomas@tuxteam.de> - 2019-06-22 12:40 +0200
                          Off-topic: Action [Was: Re: Off topic: remaja (teens) Erik Christiansen <dvalin@internode.on.net> - 2019-06-22 13:40 +0200
                          Re: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-22 23:40 +0200
                            Off topic: Carbon. Was: Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-23 01:10 +0200
                              Re: Off topic: Carbon. Was: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-23 01:50 +0200
                                Re: Off topic: Carbon. Was: Off topic: remaja (teens) Elmo <moelmoel2714@gmail.com> - 2019-06-23 03:00 +0200
                                  Re: Off topic: Carbon. Was: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-23 09:00 +0200
                                    Re: Off topic: Carbon. Was: Off topic: remaja (teens) Elmo <moelmoel2714@gmail.com> - 2019-06-23 10:00 +0200
                                Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-23 10:50 +0200
                                  Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-23 16:00 +0200
                                    Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) rhkramer@gmail.com - 2019-06-23 18:00 +0200
                                      Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic:  remaja (teens) Curt <curty@free.fr> - 2019-06-23 18:30 +0200
                                        Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-23 19:00 +0200
                                Re: Off topic: Carbon. Was: Off topic: remaja (teens) <tomas@tuxteam.de> - 2019-06-23 11:00 +0200
                                  Re: Off topic: Carbon. Was: Off topic: remaja (teens) Joe <joe@jretrading.com> - 2019-06-23 12:30 +0200
                                    Re: Off topic: Carbon. Was: Off topic: remaja (teens) Georgios <gpdsbe@mailbox.org> - 2019-06-23 20:10 +0200
                                      Re: Off topic: Carbon. Was: Off topic: remaja (teens) Joe <joe@jretrading.com> - 2019-06-23 22:50 +0200
                                        Re: Off topic: Carbon. John Hasler <jhasler@newsguy.com> - 2019-06-23 23:10 +0200
                    Teenagers (was: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?) rhkramer@gmail.com - 2019-06-22 12:30 +0200
                    Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 16:30 +0200
        Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Jimmy Johnson <field.engineer@gmail.com> - 2019-06-23 01:50 +0200
          Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Andy Smith <andy@strugglers.net> - 2019-06-23 02:10 +0200
            Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-23 11:10 +0200
            Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Richard Hector <richard@walnut.gen.nz> - 2019-06-24 02:40 +0200
              Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Andy Smith <andy@strugglers.net> - 2019-06-24 02:50 +0200
    Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-25 06:00 +0200
      Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? mick crane <mick.crane@gmail.com> - 2019-06-25 09:10 +0200
      Re: Giving remaja (teens) group full administrator privileges through  sudo - dangerous? Aidan Gauland <aidalgol@fastmail.net> - 2019-06-25 10:00 +0200
        Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Curt <curty@free.fr> - 2019-06-25 10:50 +0200
          Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-25 14:50 +0200
    Re: Giving remaja (teens) group full administrator privileges  through sudo - dangerous? andreimpopescu@gmail.com - 2019-07-02 14:50 +0200

Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →


#210305 — Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens)

Fromrhkramer@gmail.com
Date2019-06-23 18:00 +0200
SubjectRe: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens)
Message-ID<ycd4l-8tU-1@gated-at.bofh.it>
In reply to#210299
On Sunday, June 23, 2019 09:55:33 AM Nicholas Geovanis wrote:
> "If I told you you had beautiful body, would you hold it against me?"
> -same sketch

Something makes me think / remember that was not original with Monty Python -- 
I think it was Groucho Marx who said the same thing (or something very 
similar) before Monty Python.

I am curious.

[toc] | [prev] | [next] | [standalone]


#210307 — Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens)

FromCurt <curty@free.fr>
Date2019-06-23 18:30 +0200
SubjectRe: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens)
Message-ID<ycdxn-rp-9@gated-at.bofh.it>
In reply to#210305
On 2019-06-23, rhkramer@gmail.com <rhkramer@gmail.com> wrote:
> On Sunday, June 23, 2019 09:55:33 AM Nicholas Geovanis wrote:
>> "If I told you you had beautiful body, would you hold it against me?"
>> -same sketch
>
> Something makes me think / remember that was not original with Monty Python -- 
> I think it was Groucho Marx who said the same thing (or something very 
> similar) before Monty Python.

Wikipedia claims it's Groucho (from the TV show 'You Bet Your Life.'

https://en.wikipedia.org/wiki/If_I_Said_You_Had_a_Beautiful_Body_Would_You_Hold_It_Against_Me


> I am curious.
>
>


-- 
“Decisions are never really made – at best they manage to emerge, from a chaos
of peeves, whims, hallucinations and all around assholery.” – Thomas Pynchon

[toc] | [prev] | [next] | [standalone]


#210308 — Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens)

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2019-06-23 19:00 +0200
SubjectRe: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens)
Message-ID<yce0q-Bj-5@gated-at.bofh.it>
In reply to#210307

[Multipart message — attachments visible in raw view] — view raw

Cool I didn't know it was Marx Bros.
In one of their movies Groucho is hugging a tall blonde who keeps saying
"Hold me closer". Finally he says, "I get any closer I'll be on the other
side of you". :-)

On Sun, Jun 23, 2019, 11:26 AM Curt <curty@free.fr> wrote:

> On 2019-06-23, rhkramer@gmail.com <rhkramer@gmail.com> wrote:
> > On Sunday, June 23, 2019 09:55:33 AM Nicholas Geovanis wrote:
> >> "If I told you you had beautiful body, would you hold it against me?"
> >> -same sketch
> >
> > Something makes me think / remember that was not original with Monty
> Python --
> > I think it was Groucho Marx who said the same thing (or something very
> > similar) before Monty Python.
>
> Wikipedia claims it's Groucho (from the TV show 'You Bet Your Life.'
>
>
> https://en.wikipedia.org/wiki/If_I_Said_You_Had_a_Beautiful_Body_Would_You_Hold_It_Against_Me
>
>
> > I am curious.
> >
> >
>
>
> --
> “Decisions are never really made – at best they manage to emerge, from a
> chaos
> of peeves, whims, hallucinations and all around assholery.” – Thomas
> Pynchon
>
>

[toc] | [prev] | [next] | [standalone]


#210286 — Re: Off topic: Carbon. Was: Off topic: remaja (teens)

From<tomas@tuxteam.de>
Date2019-06-23 11:00 +0200
SubjectRe: Off topic: Carbon. Was: Off topic: remaja (teens)
Message-ID<yc6vU-4Be-1@gated-at.bofh.it>
In reply to#210270

[Multipart message — attachments visible in raw view] — view raw

On Sun, Jun 23, 2019 at 01:45:25AM +0200, deloptes wrote:

[...]
> too much wrong thinking - there are two fraction in science- mainstream
> supports CO2 lie. Look at arguments on both sides from real scientists (Not
> the face Potsdamer Institut für Klimaforschung <- these are fake).

Mainstream also supports round Earth lie, while we all do know Earth is
flat.

-- t

[toc] | [prev] | [next] | [standalone]


#210292 — Re: Off topic: Carbon. Was: Off topic: remaja (teens)

FromJoe <joe@jretrading.com>
Date2019-06-23 12:30 +0200
SubjectRe: Off topic: Carbon. Was: Off topic: remaja (teens)
Message-ID<yc7UZ-5ya-5@gated-at.bofh.it>
In reply to#210286
On Sun, 23 Jun 2019 10:57:26 +0200
<tomas@tuxteam.de> wrote:

> On Sun, Jun 23, 2019 at 01:45:25AM +0200, deloptes wrote:
> 
> [...]
> > too much wrong thinking - there are two fraction in science-
> > mainstream supports CO2 lie. Look at arguments on both sides from
> > real scientists (Not the face Potsdamer Institut für Klimaforschung
> > <- these are fake).  
> 
> Mainstream also supports round Earth lie, while we all do know Earth
> is flat.
> 

"Does history record any case in which the majority was right?"

R A Heinlein

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#210311 — Re: Off topic: Carbon. Was: Off topic: remaja (teens)

FromGeorgios <gpdsbe@mailbox.org>
Date2019-06-23 20:10 +0200
SubjectRe: Off topic: Carbon. Was: Off topic: remaja (teens)
Message-ID<ycf69-1t2-3@gated-at.bofh.it>
In reply to#210292
Personally
Right or wrong are highly subjective. Besides that right or wrong always
has to do with your goal. What accomplish your goal is right.
for example.
Want to be good a math?
Well the right thing to do is study after school.


Socially
You could say that every society based on its values finds something
that is considered right by the majority.
for example.
Slavery i bet 99% of us would agree that is wrong and would criticize
it. Slavery was accepted as right a couple hundred years ago.

By the way the last example probably answer to Heinlein.(based on today
values)

ps.Just felt that I had to answer that quote. Dont really like what it
implies. Of course it could be out of context.

On 6/23/19 1:26 PM, Joe wrote:

> 
> "Does history record any case in which the majority was right?"
> 
> R A Heinlein
> 

[toc] | [prev] | [next] | [standalone]


#210316 — Re: Off topic: Carbon. Was: Off topic: remaja (teens)

FromJoe <joe@jretrading.com>
Date2019-06-23 22:50 +0200
SubjectRe: Off topic: Carbon. Was: Off topic: remaja (teens)
Message-ID<ychAZ-2Mq-1@gated-at.bofh.it>
In reply to#210311
On Sun, 23 Jun 2019 21:00:10 +0300
Georgios <gpdsbe@mailbox.org> wrote:

> Personally
> Right or wrong are highly subjective. Besides that right or wrong
> always has to do with your goal. What accomplish your goal is right.
> for example.
> Want to be good a math?
> Well the right thing to do is study after school.
> 
> 
> Socially
> You could say that every society based on its values finds something
> that is considered right by the majority.
> for example.
> Slavery i bet 99% of us would agree that is wrong and would criticize
> it. Slavery was accepted as right a couple hundred years ago.
> 
And punitive levels of taxation are accepted today.

> By the way the last example probably answer to Heinlein.(based on
> today values)
> 
> ps.Just felt that I had to answer that quote. Dont really like what it
> implies. Of course it could be out of context.
> 

There is no context, it was a standalone aphorism.

> On 6/23/19 1:26 PM, Joe wrote:
> 
> > 
> > "Does history record any case in which the majority was right?"
> > 
> > R A Heinlein
> >   

OK, an exaggeration, but a general comment that the mob is almost
always misinformed, often deliberately.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#210317 — Re: Off topic: Carbon.

FromJohn Hasler <jhasler@newsguy.com>
Date2019-06-23 23:10 +0200
SubjectRe: Off topic: Carbon.
Message-ID<ychUl-38i-3@gated-at.bofh.it>
In reply to#210316
Joe wrote:
> "Does history record any case in which the majority was right?"
> R A Heinlein

Does history record any case in which the opinion of the majority was
actually known and recorded correctly and objectively?
-- 
John Hasler 
jhasler@newsguy.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#210233 — Teenagers (was: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?)

Fromrhkramer@gmail.com
Date2019-06-22 12:30 +0200
SubjectTeenagers (was: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?)
Message-ID<ybLrs-uY-11@gated-at.bofh.it>
In reply to#210221
On Saturday, June 22, 2019 04:02:11 AM Curt wrote:
> Remaja is Javanese (derived from Indonesian,
> I think) for teenager, who apparently are a PITA world-wide, 

;-)

> which is
> somehow comforting.

Well, maybe (I can see that viewpoint, it is somehow disappointing ;-)

[toc] | [prev] | [next] | [standalone]


#210249 — Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?

FromGene Heskett <gheskett@shentel.net>
Date2019-06-22 16:30 +0200
SubjectRe: Giving remaja (teens) group full administrator privileges through sudo - dangerous?
Message-ID<ybPbH-2Kr-1@gated-at.bofh.it>
In reply to#210221
On Saturday 22 June 2019 04:02:11 Curt wrote:

> On 2019-06-22, Gene Heskett <gheskett@shentel.net> wrote:
> >> You seem to be assuming that Mr. Banjaya is in the USA. While that
> >> is not impossible, given the Javanese name and non-USA usage of
> >> English, I suspect that it is not correct.
> >
> > Thats entirely possible Carl, so you could well be correct, but
> > after the war, they borrowed very heavily from us for their own com
> > rules, so even now I wouldn't expect huge deviations from our rules.
> > The final answer should come from whatever document they maintain
> > that is the equ of our 47 CFR.  And even if I had access to it, I
> > read very very little Japanese, most of that from the engrish
> > translations of Sony manuals.
>
> Not Japanese, but *Javanese*. Remaja is Javanese (derived from
> Indonesian, I think) for teenager, who apparently are a PITA
> world-wide, which is somehow comforting.
>
> > Cheers, Gene Heskett

I missed that spelling detail, but the comments are valid as long as 
there are hormones at work, and if they are not working, the line goes 
extinct. That pretty much guarantees the theory. :-)

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#210269

FromJimmy Johnson <field.engineer@gmail.com>
Date2019-06-23 01:50 +0200
Message-ID<ybXVD-7Vl-3@gated-at.bofh.it>
In reply to#210122
On 06/19/2019 09:56 PM, Bagas Sanjaya wrote:
>> That is almost as bad as having no security restrictions at all. The
>> correct thing to do would be to set permissions on the programs to
>> allow them to be run by group remaja.
> What I thought that the correct way is to configure sudoers so that 
> remaja group can access programs that they absolutely required via sudo 
> (e.g. mount for mounting USB sticks).
> 
>> I don't say this often. I would immediately fire the person
>> responsible for instituting this policy on a "production" system. (It
>> would be a good policy if the system is intended as an educational
>> environment to allow the teens to ruin things, and learn from
>> experience.)

> In fact, many television stations have most programs written for teens 
> (age 13 and older), so sysadmins there configure sudoers which allows 
> teens to behave like sysadmins themselves (by giving them full 
> administrator privileges) on their production systems. Also, parental 
> monitoring and guidance can reduce likehood of teens breaking such 
> systems. Maybe because teens are largest marketshare for TVs.


Some one mentioned mounting drives, all that and what they need can be 
configured.  There is no reason to give /sudo/root/ to anyone but the 
admin, unless it's a class on system admin.  What are you going to do 
about it?
-- 
Jimmy Johnson

Devuan Jessie - KDE 4.14.2 - AMD A8-7600 - EXT4 at sda2
Registered Linux User #380263

[toc] | [prev] | [next] | [standalone]


#210271 — Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?

FromAndy Smith <andy@strugglers.net>
Date2019-06-23 02:10 +0200
SubjectRe: Giving remaja (teens) group full administrator privileges through sudo - dangerous?
Message-ID<ybYeZ-8gU-1@gated-at.bofh.it>
In reply to#210269
Hello,

On Sat, Jun 22, 2019 at 04:44:40PM -0700, Jimmy Johnson wrote:
> Some one mentioned mounting drives, all that and what they need can be
> configured.

Also note that anyone who can use "mount" as root can trivially become
root. If countenancing allowing users to run "mount" as root I would
make scripts that only mounted the exact things to the exact places,
and then let them run those scripts as root.

andy@debtest1:~$ su - bob
Password: 
bob@debtest1:~$ whoami
bob
bob@debtest1:~$ sudo -i
[sudo] password for bob: 
Sorry, user bob is not allowed to execute '/bin/bash' as root on debtest1.vps.bitfolk.com.
bob@debtest1:~$ echo 'bob:$6$K6b1uzg.$pTNKJG/9hIgnhBL53Y2mr0rrsBBZE1xDWE0bO8E94dBlM.itel4/meJTZYL12IIOZ9ck/
3P2/j5XGbyKcKxFK/:18070:0:99999:7:::' > myshadow
bob@debtest1:~$ sudo mount --bind ./myshadow /etc/shadow
bob@debtest1:~$ su -
Password: 
root@debtest1:~# whoami
root

The password of that hash is "letmein1".

So don't give anyone sudo access to /bin/mount unless you are okay
with them being able to become root proper if they really want to.

Cheers,
Andy

[toc] | [prev] | [next] | [standalone]


#210288 — Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?

From<tomas@tuxteam.de>
Date2019-06-23 11:10 +0200
SubjectRe: Giving remaja (teens) group full administrator privileges through sudo - dangerous?
Message-ID<yc6FB-4U4-7@gated-at.bofh.it>
In reply to#210271

[Multipart message — attachments visible in raw view] — view raw

On Sun, Jun 23, 2019 at 12:07:12AM +0000, Andy Smith wrote:
> Hello,
> 
> On Sat, Jun 22, 2019 at 04:44:40PM -0700, Jimmy Johnson wrote:
> > Some one mentioned mounting drives, all that and what they need can be
> > configured.
> 
> Also note that anyone who can use "mount" as root can trivially become
> root. If countenancing allowing users to run "mount" as root I would
> make scripts that only mounted the exact things to the exact places,
> and then let them run those scripts as root.

Folks. Wise up. For "mount" there's a solution (in fstab) not needing
root. For other things, sudoers covers nearly every restricted root
usage.

Cheers
-- tomás

[toc] | [prev] | [next] | [standalone]


#210321

FromRichard Hector <richard@walnut.gen.nz>
Date2019-06-24 02:40 +0200
Message-ID<yclbA-50z-1@gated-at.bofh.it>
In reply to#210271

[Multipart message — attachments visible in raw view] — view raw

On 23/06/19 12:07 PM, Andy Smith wrote:
> Hello,
> 
> On Sat, Jun 22, 2019 at 04:44:40PM -0700, Jimmy Johnson wrote:
>> Some one mentioned mounting drives, all that and what they need can be
>> configured.
> 
> Also note that anyone who can use "mount" as root can trivially become
> root. If countenancing allowing users to run "mount" as root I would
> make scripts that only mounted the exact things to the exact places,
> and then let them run those scripts as root.
> 
> andy@debtest1:~$ su - bob
> Password: 
> bob@debtest1:~$ whoami
> bob
> bob@debtest1:~$ sudo -i
> [sudo] password for bob: 
> Sorry, user bob is not allowed to execute '/bin/bash' as root on debtest1.vps.bitfolk.com.
> bob@debtest1:~$ echo 'bob:$6$K6b1uzg.$pTNKJG/9hIgnhBL53Y2mr0rrsBBZE1xDWE0bO8E94dBlM.itel4/meJTZYL12IIOZ9ck/
> 3P2/j5XGbyKcKxFK/:18070:0:99999:7:::' > myshadow
> bob@debtest1:~$ sudo mount --bind ./myshadow /etc/shadow
> bob@debtest1:~$ su -
> Password: 
> root@debtest1:~# whoami
> root
> 
> The password of that hash is "letmein1".
> 
> So don't give anyone sudo access to /bin/mount unless you are okay
> with them being able to become root proper if they really want to.

Haven't you just set your own (bob) password there? Not saying you
couldn't set root's instead, but ... it looks like in this case you
already knew it.

Cheers,
Richard


[toc] | [prev] | [next] | [standalone]


#210322 — Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?

FromAndy Smith <andy@strugglers.net>
Date2019-06-24 02:50 +0200
SubjectRe: Giving remaja (teens) group full administrator privileges through sudo - dangerous?
Message-ID<ycllf-53N-1@gated-at.bofh.it>
In reply to#210321
Hello,

On Mon, Jun 24, 2019 at 12:34:36PM +1200, Richard Hector wrote:
> On 23/06/19 12:07 PM, Andy Smith wrote:
> > andy@debtest1:~$ su - bob
> > Password: 
> > bob@debtest1:~$ whoami
> > bob
> > bob@debtest1:~$ sudo -i
> > [sudo] password for bob: 
> > Sorry, user bob is not allowed to execute '/bin/bash' as root on debtest1.vps.bitfolk.com.
> > bob@debtest1:~$ echo 'bob:$6$K6b1uzg.$pTNKJG/9hIgnhBL53Y2mr0rrsBBZE1xDWE0bO8E94dBlM.itel4/meJTZYL12IIOZ9ck/
> > 3P2/j5XGbyKcKxFK/:18070:0:99999:7:::' > myshadow
> > bob@debtest1:~$ sudo mount --bind ./myshadow /etc/shadow
> > bob@debtest1:~$ su -
> > Password: 
> > root@debtest1:~# whoami
> > root

[…]

> Haven't you just set your own (bob) password there? Not saying you
> couldn't set root's instead, but ... it looks like in this case you
> already knew it.

Yes, it was a mispaste from an earlier line in my screen history.
Sorry about that.

Point is you can take a hash that you already know, e.g. your own,
write it into a new shadow file but make it be for the root user,
not your own user, e.g.:

bob@debtest1:~$ echo 'root:$6$K6b1uzg.$pTNKJG/9hIgnhBL53Y2mr0rrsBBZE1xDWE0bO8E94dBlM.itel4/meJTZYL12IIOZ9ck/3P2/j5XGbyKcKxFK/:18070:0:99999:7:::' > myshadow

and then since you are able to use mount as root you can bind mount
your new shadow file over the system's real shadow file, hence
effectively resetting root's password:

bob@debtest1:~$ sudo mount --bind ./myshadow /etc/shadow
bob@debtest1:~$ su -
Password: 
root@debtest1:~# whoami
root

Since you can bind mount files and directories, root access to
"mount" means root access to every part of the existing filesystem
so there's many many ways of getting a root shell from that.

Try it. :) But maybe on a test host as bind-mounting over something
important may completely break your system.

Cheers,
Andy

[toc] | [prev] | [next] | [standalone]


#210350

FromBagas Sanjaya <bagasdotme@gmail.com>
Date2019-06-25 06:00 +0200
Message-ID<ycKMF-3Jf-3@gated-at.bofh.it>
In reply to#210087
On 24/06/19 06.27, Aidan Gauland wrote:

> I can't really offer an opinion on whether it is dangerous without a 
> more detailed hypothetical scenario, but I would say that is 
> overbroad, and this rule should be narrowed down to only allow running 
> certain commands via sudo as required for this group to perform their 
> work.

In this hypothetical scenario, the sudoers rule is applied to ALL 
systems, including production ones, and sysadmins doesn't have proper 
backups.

[toc] | [prev] | [next] | [standalone]


#210352

Frommick crane <mick.crane@gmail.com>
Date2019-06-25 09:10 +0200
Message-ID<ycNKx-5LO-7@gated-at.bofh.it>
In reply to#210350
On 2019-06-25 04:38, Bagas Sanjaya wrote:
> On 24/06/19 06.27, Aidan Gauland wrote:
> 
>> I can't really offer an opinion on whether it is dangerous without a 
>> more detailed hypothetical scenario, but I would say that is 
>> overbroad, and this rule should be narrowed down to only allow running 
>> certain commands via sudo as required for this group to perform their 
>> work.
> 
> In this hypothetical scenario, the sudoers rule is applied to ALL
> systems, including production ones, and sysadmins doesn't have proper
> backups.

I've concluded that you are asking for assistance with some artistic 
idea applying anarchist political theory to TV film production but are 
confusing production method with production tools.
When film/ tape was flammable an editor wouldn't let a random person 
with a flame thrower into his editing room likewise a computer whose 
function might be video editing is a tool of many delicate parts and if 
some part of it is broken then it likely will stop working.

mick
-- 
Key ID    4BFEBB31

[toc] | [prev] | [next] | [standalone]


#210355

FromAidan Gauland <aidalgol@fastmail.net>
Date2019-06-25 10:00 +0200
Message-ID<ycOwV-62n-1@gated-at.bofh.it>
In reply to#210350
On 25/06/19 3:38 PM, Bagas Sanjaya wrote:
> On 24/06/19 06.27, Aidan Gauland wrote:
>
>> I can't really offer an opinion on whether it is dangerous without a
>> more detailed hypothetical scenario, but I would say that is
>> overbroad, and this rule should be narrowed down to only allow
>> running certain commands via sudo as required for this group to
>> perform their work.
>
> In this hypothetical scenario, the sudoers rule is applied to ALL
> systems, including production ones, and sysadmins doesn't have proper
> backups.
OK, not having a (good) backup system is definitely bad.  You should
always have that even if your security is very tight, in case something
slips through, or an admin makes a mistake.

[toc] | [prev] | [next] | [standalone]


#210358 — Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?

FromCurt <curty@free.fr>
Date2019-06-25 10:50 +0200
SubjectRe: Giving remaja (teens) group full administrator privileges through sudo - dangerous?
Message-ID<ycPjk-6y7-11@gated-at.bofh.it>
In reply to#210355
On 2019-06-25, Aidan Gauland <aidalgol@fastmail.net> wrote:
>>
>> In this hypothetical scenario, the sudoers rule is applied to ALL
>> systems, including production ones, and sysadmins doesn't have proper
>> backups.
> OK, not having a (good) backup system is definitely bad.  You should
> always have that even if your security is very tight, in case something
> slips through, or an admin makes a mistake.

I'd just get a better hypothetical scenario if I were the OP (they're a
dime a dozen anyway) because as it stands now his is so completely up
the wazoo it's really the only sensible advice.

[toc] | [prev] | [next] | [standalone]


#210370 — Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2019-06-25 14:50 +0200
SubjectRe: Giving remaja (teens) group full administrator privileges through sudo - dangerous?
Message-ID<ycT3z-mb-15@gated-at.bofh.it>
In reply to#210358
On Tue, Jun 25, 2019 at 10:38:10AM +0700, Bagas Sanjaya wrote:
> In this hypothetical scenario, the sudoers rule is applied to ALL systems,
> including production ones, and sysadmins doesn't have proper backups.

On Tue, Jun 25, 2019 at 08:45:13AM -0000, Curt wrote:
> I'd just get a better hypothetical scenario if I were the OP (they're a
> dime a dozen anyway) because as it stands now his is so completely up
> the wazoo it's really the only sensible advice.

I'm about 30% convinced this is all some sort of elaborate troll.

40% chance this person is just completely incompetent, and these
decisions will mean the end of their employment in this field.

30% chance that it's a language/translation issue, and the actual
intent is not being conveyed correctly, despite repeated requests for
clarification.

(Tt's probably some combination of the three.)

[toc] | [prev] | [next] | [standalone]


Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →

Back to top | Article view | linux.debian.user


csiph-web