Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #229715

Re: Emergency mode when root account locked

From Andrei POPESCU <andreimpopescu@gmail.com>
Newsgroups linux.debian.user
Subject Re: Emergency mode when root account locked
Date 2020-12-12 20:00 +0100
Message-ID <BlihA-58L-13@gated-at.bofh.it> (permalink)
References <Bl0E2-2Z0-7@gated-at.bofh.it> <Bl38R-4j0-1@gated-at.bofh.it> <Bl8BA-7MS-5@gated-at.bofh.it> <BlbJ8-19L-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Sb, 12 dec 20, 22:53:41, Keith Bainbridge wrote:
> On 12/12/20 7:29 pm, Andrei POPESCU wrote:
> > > AND run sudo as root, for additional safety
> > Is this supposed to be ironic? I really can't tell.
> 
> 
> There was a detailed discussion here about sudo being a security issue
> on our systems. It appears to be default in debian 10, so most of us get
> it as default. I looked at replacing sudo.
> 
> I found an article that explained how to strengthen it by forcing sudo
> to require root password.
 
To my non-native understanding of English "run foo as root" usually 
means one first gains root privileges (by whatever means) and then runs 
that program with the elevated privileges.

In the context of the text you were replying to it seemed to me you 
might just be ironic (though admittedly I did also consider you might be 
referring to the 'targetpw' option in 'sudoers').

> If somebody breaks in, they now need my root password to execute
> commands that require root permissions (except a couple that I have
> given nopasswd privilege).

If a user's normal account is compromised most of what matters is 
already compromised as well. The root access is just icing on the cake 
and can be easily obtained with a keylogger (which an attacker would 
need anyway for the all the other goodies).

https://xkcd.com/1200/

Otherwise a probably quite simple 'sudo' script[1] in ~/.local/bin 
should do the trick as well: present a password prompt, save the 
password somewhere safe, pretend to fail and then call the real 
'sudo'[3].

After all, how many users are calling 'sudo' with the full path?


Instead I would suggest admin tasks should be performed from a dedicated 
*normal* account, using sudo just for those commands that require 
elevated privileges.

This provides some additional security, while also being slightly safer 
from accidental mistakes than logging in as root directly.


[2] which by default is added to $PATH on Debian.
[1] If I'm bored enough I might just write such a script myself.
[3] and maybe deletes itself to remove traces

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Emergency mode when root account locked deandre <d.gopburn10@gmail.com> - 2020-12-04 13:20 +0100
  Re: Emergency mode when root account locked Greg Wooledge <wooledg@eeg.ccf.org> - 2020-12-04 14:20 +0100
    Re: Emergency mode when root account locked Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-05 11:50 +0100
      Re: Emergency mode when root account locked Greg Wooledge <wooledg@eeg.ccf.org> - 2020-12-07 16:20 +0100
        Re: Emergency mode when root account locked Tixy <tixy@yxit.co.uk> - 2020-12-07 16:40 +0100
          Re: Emergency mode when root account locked Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-08 10:00 +0100
            Re: Emergency mode when root account locked Tixy <tixy@yxit.co.uk> - 2020-12-08 10:20 +0100
              Re: Emergency mode when root account locked deloptes <deloptes@gmail.com> - 2020-12-08 12:00 +0100
        Re: Emergency mode when root account locked grumpy@mailfence.com - 2020-12-07 16:40 +0100
          Re: Emergency mode when root account locked Celejar <celejar@gmail.com> - 2020-12-09 01:50 +0100
        Re: Emergency mode when root account locked Fabrice BAUZAC <noon@mykolab.com> - 2020-12-12 01:10 +0100
          Re: Emergency mode when root account locked Keith Bainbridge <ke1thozgroups@gmx.com> - 2020-12-12 03:50 +0100
            Re: Emergency mode when root account locked Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-12 09:40 +0100
              Re: Emergency mode when root account locked Keith Bainbridge <ke1thozgroups@gmx.com> - 2020-12-12 13:00 +0100
                Re: Emergency mode when root account locked Tixy <tixy@yxit.co.uk> - 2020-12-12 14:10 +0100
                Re: Emergency mode when root account locked Brian <ad44@cityscape.co.uk> - 2020-12-12 14:10 +0100
                Re: Emergency mode when root account locked "Andrew M.A. Cater" <amacater@einval.com> - 2020-12-12 14:20 +0100
                Re: Emergency mode when root account locked Brian <ad44@cityscape.co.uk> - 2020-12-12 14:50 +0100
                Re: Emergency mode when root account locked Kenneth Parker <sea7kenp@gmail.com> - 2020-12-12 17:40 +0100
                Re: Emergency mode when root account locked "Andrew M.A. Cater" <amacater@einval.com> - 2020-12-12 18:20 +0100
                Re: Emergency mode when root account locked Brian <ad44@cityscape.co.uk> - 2020-12-12 18:50 +0100
                Re: Emergency mode when root account locked Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-12 20:00 +0100
                Re: Emergency mode when root account locked Brian <ad44@cityscape.co.uk> - 2020-12-12 21:20 +0100
          Re: Emergency mode when root account locked Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2020-12-12 15:20 +0100
            Re: Emergency mode when root account locked Marco Möller <talby@debianlists.mobilxpress.net> - 2020-12-12 15:40 +0100
              Re: Emergency mode when root account locked Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2020-12-12 15:50 +0100
            Re: Emergency mode when root account locked deloptes <deloptes@gmail.com> - 2020-12-13 00:50 +0100
        Bug#977358: release-notes: document how to make the rescue mode usable if no root password is set (buster) Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-14 12:20 +0100
          Re: Bug#977358: release-notes: document how to make the rescue mode  usable if no root password is set (buster) nickgeovanis <nickgeovanis@gmail.com> - 2020-12-14 13:40 +0100
          Re: Bug#977358: release-notes: document how to make the rescue mode  usable if no root password is set (buster) "Alexander V. Makartsev" <avbetev@gmail.com> - 2021-03-21 09:50 +0100
  Re: Emergency mode when root account locked Marco Möller <talby@debianlists.mobilxpress.net> - 2020-12-05 15:10 +0100

csiph-web