Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #210087 > unrolled thread
| Started by | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| First post | 2019-06-19 06:30 +0200 |
| Last post | 2019-07-02 14:50 +0200 |
| Articles | 20 on this page of 61 — 24 participants |
Back to article view | Back to linux.debian.user
Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-19 06:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? john doe <johndoe65534@mail.com> - 2019-06-19 08:00 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-19 08:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Carl <carlf@panix.com> - 2019-06-19 13:40 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 07:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Richard Hector <richard@walnut.gen.nz> - 2019-06-20 07:40 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 09:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Curt <curty@free.fr> - 2019-06-20 11:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? rhkramer@gmail.com - 2019-06-20 14:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Carl <carlf@panix.com> - 2019-06-20 13:00 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-20 14:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-20 18:40 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Carl Fink <carlf@panix.com> - 2019-06-21 21:50 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-22 01:00 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 04:30 +0200
Re: Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-22 10:40 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? rhkramer@gmail.com - 2019-06-22 12:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 17:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Brad Rogers <brad@fineby.me.uk> - 2019-06-22 18:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 18:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Curt <curty@free.fr> - 2019-06-22 18:50 +0200
Re: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-22 10:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 16:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Carl <carlf@panix.com> - 2019-06-22 14:20 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 02:40 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Curt <curty@free.fr> - 2019-06-22 10:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-22 10:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-22 10:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? deloptes <deloptes@gmail.com> - 2019-06-22 11:50 +0200
Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-22 12:30 +0200
Re: Off topic: remaja (teens) <tomas@tuxteam.de> - 2019-06-22 12:40 +0200
Off-topic: Action [Was: Re: Off topic: remaja (teens) Erik Christiansen <dvalin@internode.on.net> - 2019-06-22 13:40 +0200
Re: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-22 23:40 +0200
Off topic: Carbon. Was: Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-23 01:10 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-23 01:50 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Elmo <moelmoel2714@gmail.com> - 2019-06-23 03:00 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) deloptes <deloptes@gmail.com> - 2019-06-23 09:00 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Elmo <moelmoel2714@gmail.com> - 2019-06-23 10:00 +0200
Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) "Thomas Schmitt" <scdbackup@gmx.net> - 2019-06-23 10:50 +0200
Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-23 16:00 +0200
Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) rhkramer@gmail.com - 2019-06-23 18:00 +0200
Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) Curt <curty@free.fr> - 2019-06-23 18:30 +0200
Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-23 19:00 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) <tomas@tuxteam.de> - 2019-06-23 11:00 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Joe <joe@jretrading.com> - 2019-06-23 12:30 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Georgios <gpdsbe@mailbox.org> - 2019-06-23 20:10 +0200
Re: Off topic: Carbon. Was: Off topic: remaja (teens) Joe <joe@jretrading.com> - 2019-06-23 22:50 +0200
Re: Off topic: Carbon. John Hasler <jhasler@newsguy.com> - 2019-06-23 23:10 +0200
Teenagers (was: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?) rhkramer@gmail.com - 2019-06-22 12:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Gene Heskett <gheskett@shentel.net> - 2019-06-22 16:30 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Jimmy Johnson <field.engineer@gmail.com> - 2019-06-23 01:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Andy Smith <andy@strugglers.net> - 2019-06-23 02:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? <tomas@tuxteam.de> - 2019-06-23 11:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Richard Hector <richard@walnut.gen.nz> - 2019-06-24 02:40 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Andy Smith <andy@strugglers.net> - 2019-06-24 02:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Bagas Sanjaya <bagasdotme@gmail.com> - 2019-06-25 06:00 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? mick crane <mick.crane@gmail.com> - 2019-06-25 09:10 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Aidan Gauland <aidalgol@fastmail.net> - 2019-06-25 10:00 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Curt <curty@free.fr> - 2019-06-25 10:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-25 14:50 +0200
Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? andreimpopescu@gmail.com - 2019-07-02 14:50 +0200
Page 3 of 4 — ← Prev page 1 2 [3] 4 Next page →
| From | rhkramer@gmail.com |
|---|---|
| Date | 2019-06-23 18:00 +0200 |
| Subject | Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) |
| Message-ID | <ycd4l-8tU-1@gated-at.bofh.it> |
| In reply to | #210299 |
On Sunday, June 23, 2019 09:55:33 AM Nicholas Geovanis wrote: > "If I told you you had beautiful body, would you hold it against me?" > -same sketch Something makes me think / remember that was not original with Monty Python -- I think it was Groucho Marx who said the same thing (or something very similar) before Monty Python. I am curious.
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2019-06-23 18:30 +0200 |
| Subject | Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) |
| Message-ID | <ycdxn-rp-9@gated-at.bofh.it> |
| In reply to | #210305 |
On 2019-06-23, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > On Sunday, June 23, 2019 09:55:33 AM Nicholas Geovanis wrote: >> "If I told you you had beautiful body, would you hold it against me?" >> -same sketch > > Something makes me think / remember that was not original with Monty Python -- > I think it was Groucho Marx who said the same thing (or something very > similar) before Monty Python. Wikipedia claims it's Groucho (from the TV show 'You Bet Your Life.' https://en.wikipedia.org/wiki/If_I_Said_You_Had_a_Beautiful_Body_Would_You_Hold_It_Against_Me > I am curious. > > -- “Decisions are never really made – at best they manage to emerge, from a chaos of peeves, whims, hallucinations and all around assholery.” – Thomas Pynchon
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2019-06-23 19:00 +0200 |
| Subject | Re: Off topic: German. Was: Off topic: Carbon. Was: Off topic: remaja (teens) |
| Message-ID | <yce0q-Bj-5@gated-at.bofh.it> |
| In reply to | #210307 |
[Multipart message — attachments visible in raw view] — view raw
Cool I didn't know it was Marx Bros. In one of their movies Groucho is hugging a tall blonde who keeps saying "Hold me closer". Finally he says, "I get any closer I'll be on the other side of you". :-) On Sun, Jun 23, 2019, 11:26 AM Curt <curty@free.fr> wrote: > On 2019-06-23, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > On Sunday, June 23, 2019 09:55:33 AM Nicholas Geovanis wrote: > >> "If I told you you had beautiful body, would you hold it against me?" > >> -same sketch > > > > Something makes me think / remember that was not original with Monty > Python -- > > I think it was Groucho Marx who said the same thing (or something very > > similar) before Monty Python. > > Wikipedia claims it's Groucho (from the TV show 'You Bet Your Life.' > > > https://en.wikipedia.org/wiki/If_I_Said_You_Had_a_Beautiful_Body_Would_You_Hold_It_Against_Me > > > > I am curious. > > > > > > > -- > “Decisions are never really made – at best they manage to emerge, from a > chaos > of peeves, whims, hallucinations and all around assholery.” – Thomas > Pynchon > >
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-06-23 11:00 +0200 |
| Subject | Re: Off topic: Carbon. Was: Off topic: remaja (teens) |
| Message-ID | <yc6vU-4Be-1@gated-at.bofh.it> |
| In reply to | #210270 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, Jun 23, 2019 at 01:45:25AM +0200, deloptes wrote: [...] > too much wrong thinking - there are two fraction in science- mainstream > supports CO2 lie. Look at arguments on both sides from real scientists (Not > the face Potsdamer Institut für Klimaforschung <- these are fake). Mainstream also supports round Earth lie, while we all do know Earth is flat. -- t
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2019-06-23 12:30 +0200 |
| Subject | Re: Off topic: Carbon. Was: Off topic: remaja (teens) |
| Message-ID | <yc7UZ-5ya-5@gated-at.bofh.it> |
| In reply to | #210286 |
On Sun, 23 Jun 2019 10:57:26 +0200 <tomas@tuxteam.de> wrote: > On Sun, Jun 23, 2019 at 01:45:25AM +0200, deloptes wrote: > > [...] > > too much wrong thinking - there are two fraction in science- > > mainstream supports CO2 lie. Look at arguments on both sides from > > real scientists (Not the face Potsdamer Institut für Klimaforschung > > <- these are fake). > > Mainstream also supports round Earth lie, while we all do know Earth > is flat. > "Does history record any case in which the majority was right?" R A Heinlein -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Georgios <gpdsbe@mailbox.org> |
|---|---|
| Date | 2019-06-23 20:10 +0200 |
| Subject | Re: Off topic: Carbon. Was: Off topic: remaja (teens) |
| Message-ID | <ycf69-1t2-3@gated-at.bofh.it> |
| In reply to | #210292 |
Personally Right or wrong are highly subjective. Besides that right or wrong always has to do with your goal. What accomplish your goal is right. for example. Want to be good a math? Well the right thing to do is study after school. Socially You could say that every society based on its values finds something that is considered right by the majority. for example. Slavery i bet 99% of us would agree that is wrong and would criticize it. Slavery was accepted as right a couple hundred years ago. By the way the last example probably answer to Heinlein.(based on today values) ps.Just felt that I had to answer that quote. Dont really like what it implies. Of course it could be out of context. On 6/23/19 1:26 PM, Joe wrote: > > "Does history record any case in which the majority was right?" > > R A Heinlein >
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2019-06-23 22:50 +0200 |
| Subject | Re: Off topic: Carbon. Was: Off topic: remaja (teens) |
| Message-ID | <ychAZ-2Mq-1@gated-at.bofh.it> |
| In reply to | #210311 |
On Sun, 23 Jun 2019 21:00:10 +0300 Georgios <gpdsbe@mailbox.org> wrote: > Personally > Right or wrong are highly subjective. Besides that right or wrong > always has to do with your goal. What accomplish your goal is right. > for example. > Want to be good a math? > Well the right thing to do is study after school. > > > Socially > You could say that every society based on its values finds something > that is considered right by the majority. > for example. > Slavery i bet 99% of us would agree that is wrong and would criticize > it. Slavery was accepted as right a couple hundred years ago. > And punitive levels of taxation are accepted today. > By the way the last example probably answer to Heinlein.(based on > today values) > > ps.Just felt that I had to answer that quote. Dont really like what it > implies. Of course it could be out of context. > There is no context, it was a standalone aphorism. > On 6/23/19 1:26 PM, Joe wrote: > > > > > "Does history record any case in which the majority was right?" > > > > R A Heinlein > > OK, an exaggeration, but a general comment that the mob is almost always misinformed, often deliberately. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <jhasler@newsguy.com> |
|---|---|
| Date | 2019-06-23 23:10 +0200 |
| Subject | Re: Off topic: Carbon. |
| Message-ID | <ychUl-38i-3@gated-at.bofh.it> |
| In reply to | #210316 |
Joe wrote: > "Does history record any case in which the majority was right?" > R A Heinlein Does history record any case in which the opinion of the majority was actually known and recorded correctly and objectively? -- John Hasler jhasler@newsguy.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2019-06-22 12:30 +0200 |
| Subject | Teenagers (was: Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous?) |
| Message-ID | <ybLrs-uY-11@gated-at.bofh.it> |
| In reply to | #210221 |
On Saturday, June 22, 2019 04:02:11 AM Curt wrote: > Remaja is Javanese (derived from Indonesian, > I think) for teenager, who apparently are a PITA world-wide, ;-) > which is > somehow comforting. Well, maybe (I can see that viewpoint, it is somehow disappointing ;-)
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-22 16:30 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybPbH-2Kr-1@gated-at.bofh.it> |
| In reply to | #210221 |
On Saturday 22 June 2019 04:02:11 Curt wrote: > On 2019-06-22, Gene Heskett <gheskett@shentel.net> wrote: > >> You seem to be assuming that Mr. Banjaya is in the USA. While that > >> is not impossible, given the Javanese name and non-USA usage of > >> English, I suspect that it is not correct. > > > > Thats entirely possible Carl, so you could well be correct, but > > after the war, they borrowed very heavily from us for their own com > > rules, so even now I wouldn't expect huge deviations from our rules. > > The final answer should come from whatever document they maintain > > that is the equ of our 47 CFR. And even if I had access to it, I > > read very very little Japanese, most of that from the engrish > > translations of Sony manuals. > > Not Japanese, but *Javanese*. Remaja is Javanese (derived from > Indonesian, I think) for teenager, who apparently are a PITA > world-wide, which is somehow comforting. > > > Cheers, Gene Heskett I missed that spelling detail, but the comments are valid as long as there are hormones at work, and if they are not working, the line goes extinct. That pretty much guarantees the theory. :-) Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Jimmy Johnson <field.engineer@gmail.com> |
|---|---|
| Date | 2019-06-23 01:50 +0200 |
| Message-ID | <ybXVD-7Vl-3@gated-at.bofh.it> |
| In reply to | #210122 |
On 06/19/2019 09:56 PM, Bagas Sanjaya wrote: >> That is almost as bad as having no security restrictions at all. The >> correct thing to do would be to set permissions on the programs to >> allow them to be run by group remaja. > What I thought that the correct way is to configure sudoers so that > remaja group can access programs that they absolutely required via sudo > (e.g. mount for mounting USB sticks). > >> I don't say this often. I would immediately fire the person >> responsible for instituting this policy on a "production" system. (It >> would be a good policy if the system is intended as an educational >> environment to allow the teens to ruin things, and learn from >> experience.) > In fact, many television stations have most programs written for teens > (age 13 and older), so sysadmins there configure sudoers which allows > teens to behave like sysadmins themselves (by giving them full > administrator privileges) on their production systems. Also, parental > monitoring and guidance can reduce likehood of teens breaking such > systems. Maybe because teens are largest marketshare for TVs. Some one mentioned mounting drives, all that and what they need can be configured. There is no reason to give /sudo/root/ to anyone but the admin, unless it's a class on system admin. What are you going to do about it? -- Jimmy Johnson Devuan Jessie - KDE 4.14.2 - AMD A8-7600 - EXT4 at sda2 Registered Linux User #380263
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2019-06-23 02:10 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ybYeZ-8gU-1@gated-at.bofh.it> |
| In reply to | #210269 |
Hello, On Sat, Jun 22, 2019 at 04:44:40PM -0700, Jimmy Johnson wrote: > Some one mentioned mounting drives, all that and what they need can be > configured. Also note that anyone who can use "mount" as root can trivially become root. If countenancing allowing users to run "mount" as root I would make scripts that only mounted the exact things to the exact places, and then let them run those scripts as root. andy@debtest1:~$ su - bob Password: bob@debtest1:~$ whoami bob bob@debtest1:~$ sudo -i [sudo] password for bob: Sorry, user bob is not allowed to execute '/bin/bash' as root on debtest1.vps.bitfolk.com. bob@debtest1:~$ echo 'bob:$6$K6b1uzg.$pTNKJG/9hIgnhBL53Y2mr0rrsBBZE1xDWE0bO8E94dBlM.itel4/meJTZYL12IIOZ9ck/ 3P2/j5XGbyKcKxFK/:18070:0:99999:7:::' > myshadow bob@debtest1:~$ sudo mount --bind ./myshadow /etc/shadow bob@debtest1:~$ su - Password: root@debtest1:~# whoami root The password of that hash is "letmein1". So don't give anyone sudo access to /bin/mount unless you are okay with them being able to become root proper if they really want to. Cheers, Andy
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2019-06-23 11:10 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <yc6FB-4U4-7@gated-at.bofh.it> |
| In reply to | #210271 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, Jun 23, 2019 at 12:07:12AM +0000, Andy Smith wrote: > Hello, > > On Sat, Jun 22, 2019 at 04:44:40PM -0700, Jimmy Johnson wrote: > > Some one mentioned mounting drives, all that and what they need can be > > configured. > > Also note that anyone who can use "mount" as root can trivially become > root. If countenancing allowing users to run "mount" as root I would > make scripts that only mounted the exact things to the exact places, > and then let them run those scripts as root. Folks. Wise up. For "mount" there's a solution (in fstab) not needing root. For other things, sudoers covers nearly every restricted root usage. Cheers -- tomás
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2019-06-24 02:40 +0200 |
| Message-ID | <yclbA-50z-1@gated-at.bofh.it> |
| In reply to | #210271 |
[Multipart message — attachments visible in raw view] — view raw
On 23/06/19 12:07 PM, Andy Smith wrote: > Hello, > > On Sat, Jun 22, 2019 at 04:44:40PM -0700, Jimmy Johnson wrote: >> Some one mentioned mounting drives, all that and what they need can be >> configured. > > Also note that anyone who can use "mount" as root can trivially become > root. If countenancing allowing users to run "mount" as root I would > make scripts that only mounted the exact things to the exact places, > and then let them run those scripts as root. > > andy@debtest1:~$ su - bob > Password: > bob@debtest1:~$ whoami > bob > bob@debtest1:~$ sudo -i > [sudo] password for bob: > Sorry, user bob is not allowed to execute '/bin/bash' as root on debtest1.vps.bitfolk.com. > bob@debtest1:~$ echo 'bob:$6$K6b1uzg.$pTNKJG/9hIgnhBL53Y2mr0rrsBBZE1xDWE0bO8E94dBlM.itel4/meJTZYL12IIOZ9ck/ > 3P2/j5XGbyKcKxFK/:18070:0:99999:7:::' > myshadow > bob@debtest1:~$ sudo mount --bind ./myshadow /etc/shadow > bob@debtest1:~$ su - > Password: > root@debtest1:~# whoami > root > > The password of that hash is "letmein1". > > So don't give anyone sudo access to /bin/mount unless you are okay > with them being able to become root proper if they really want to. Haven't you just set your own (bob) password there? Not saying you couldn't set root's instead, but ... it looks like in this case you already knew it. Cheers, Richard
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2019-06-24 02:50 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ycllf-53N-1@gated-at.bofh.it> |
| In reply to | #210321 |
Hello, On Mon, Jun 24, 2019 at 12:34:36PM +1200, Richard Hector wrote: > On 23/06/19 12:07 PM, Andy Smith wrote: > > andy@debtest1:~$ su - bob > > Password: > > bob@debtest1:~$ whoami > > bob > > bob@debtest1:~$ sudo -i > > [sudo] password for bob: > > Sorry, user bob is not allowed to execute '/bin/bash' as root on debtest1.vps.bitfolk.com. > > bob@debtest1:~$ echo 'bob:$6$K6b1uzg.$pTNKJG/9hIgnhBL53Y2mr0rrsBBZE1xDWE0bO8E94dBlM.itel4/meJTZYL12IIOZ9ck/ > > 3P2/j5XGbyKcKxFK/:18070:0:99999:7:::' > myshadow > > bob@debtest1:~$ sudo mount --bind ./myshadow /etc/shadow > > bob@debtest1:~$ su - > > Password: > > root@debtest1:~# whoami > > root […] > Haven't you just set your own (bob) password there? Not saying you > couldn't set root's instead, but ... it looks like in this case you > already knew it. Yes, it was a mispaste from an earlier line in my screen history. Sorry about that. Point is you can take a hash that you already know, e.g. your own, write it into a new shadow file but make it be for the root user, not your own user, e.g.: bob@debtest1:~$ echo 'root:$6$K6b1uzg.$pTNKJG/9hIgnhBL53Y2mr0rrsBBZE1xDWE0bO8E94dBlM.itel4/meJTZYL12IIOZ9ck/3P2/j5XGbyKcKxFK/:18070:0:99999:7:::' > myshadow and then since you are able to use mount as root you can bind mount your new shadow file over the system's real shadow file, hence effectively resetting root's password: bob@debtest1:~$ sudo mount --bind ./myshadow /etc/shadow bob@debtest1:~$ su - Password: root@debtest1:~# whoami root Since you can bind mount files and directories, root access to "mount" means root access to every part of the existing filesystem so there's many many ways of getting a root shell from that. Try it. :) But maybe on a test host as bind-mounting over something important may completely break your system. Cheers, Andy
[toc] | [prev] | [next] | [standalone]
| From | Bagas Sanjaya <bagasdotme@gmail.com> |
|---|---|
| Date | 2019-06-25 06:00 +0200 |
| Message-ID | <ycKMF-3Jf-3@gated-at.bofh.it> |
| In reply to | #210087 |
On 24/06/19 06.27, Aidan Gauland wrote: > I can't really offer an opinion on whether it is dangerous without a > more detailed hypothetical scenario, but I would say that is > overbroad, and this rule should be narrowed down to only allow running > certain commands via sudo as required for this group to perform their > work. In this hypothetical scenario, the sudoers rule is applied to ALL systems, including production ones, and sysadmins doesn't have proper backups.
[toc] | [prev] | [next] | [standalone]
| From | mick crane <mick.crane@gmail.com> |
|---|---|
| Date | 2019-06-25 09:10 +0200 |
| Message-ID | <ycNKx-5LO-7@gated-at.bofh.it> |
| In reply to | #210350 |
On 2019-06-25 04:38, Bagas Sanjaya wrote: > On 24/06/19 06.27, Aidan Gauland wrote: > >> I can't really offer an opinion on whether it is dangerous without a >> more detailed hypothetical scenario, but I would say that is >> overbroad, and this rule should be narrowed down to only allow running >> certain commands via sudo as required for this group to perform their >> work. > > In this hypothetical scenario, the sudoers rule is applied to ALL > systems, including production ones, and sysadmins doesn't have proper > backups. I've concluded that you are asking for assistance with some artistic idea applying anarchist political theory to TV film production but are confusing production method with production tools. When film/ tape was flammable an editor wouldn't let a random person with a flame thrower into his editing room likewise a computer whose function might be video editing is a tool of many delicate parts and if some part of it is broken then it likely will stop working. mick -- Key ID 4BFEBB31
[toc] | [prev] | [next] | [standalone]
| From | Aidan Gauland <aidalgol@fastmail.net> |
|---|---|
| Date | 2019-06-25 10:00 +0200 |
| Message-ID | <ycOwV-62n-1@gated-at.bofh.it> |
| In reply to | #210350 |
On 25/06/19 3:38 PM, Bagas Sanjaya wrote: > On 24/06/19 06.27, Aidan Gauland wrote: > >> I can't really offer an opinion on whether it is dangerous without a >> more detailed hypothetical scenario, but I would say that is >> overbroad, and this rule should be narrowed down to only allow >> running certain commands via sudo as required for this group to >> perform their work. > > In this hypothetical scenario, the sudoers rule is applied to ALL > systems, including production ones, and sysadmins doesn't have proper > backups. OK, not having a (good) backup system is definitely bad. You should always have that even if your security is very tight, in case something slips through, or an admin makes a mistake.
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2019-06-25 10:50 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ycPjk-6y7-11@gated-at.bofh.it> |
| In reply to | #210355 |
On 2019-06-25, Aidan Gauland <aidalgol@fastmail.net> wrote: >> >> In this hypothetical scenario, the sudoers rule is applied to ALL >> systems, including production ones, and sysadmins doesn't have proper >> backups. > OK, not having a (good) backup system is definitely bad. You should > always have that even if your security is very tight, in case something > slips through, or an admin makes a mistake. I'd just get a better hypothetical scenario if I were the OP (they're a dime a dozen anyway) because as it stands now his is so completely up the wazoo it's really the only sensible advice.
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2019-06-25 14:50 +0200 |
| Subject | Re: Giving remaja (teens) group full administrator privileges through sudo - dangerous? |
| Message-ID | <ycT3z-mb-15@gated-at.bofh.it> |
| In reply to | #210358 |
On Tue, Jun 25, 2019 at 10:38:10AM +0700, Bagas Sanjaya wrote: > In this hypothetical scenario, the sudoers rule is applied to ALL systems, > including production ones, and sysadmins doesn't have proper backups. On Tue, Jun 25, 2019 at 08:45:13AM -0000, Curt wrote: > I'd just get a better hypothetical scenario if I were the OP (they're a > dime a dozen anyway) because as it stands now his is so completely up > the wazoo it's really the only sensible advice. I'm about 30% convinced this is all some sort of elaborate troll. 40% chance this person is just completely incompetent, and these decisions will mean the end of their employment in this field. 30% chance that it's a language/translation issue, and the actual intent is not being conveyed correctly, despite repeated requests for clarification. (Tt's probably some combination of the three.)
[toc] | [prev] | [next] | [standalone]
Page 3 of 4 — ← Prev page 1 2 [3] 4 Next page →
Back to top | Article view | linux.debian.user
csiph-web