The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > OS Specific Forums > Linux
Google UNIX.COM


Linux RedHat, Ubuntu, SUSE, Fedora, Debian, Mandriva, Slackware, Gentoo linux, PCLinuxOS. All Linux questions here!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
sudo question melias Security 12 05-26-2008 01:10 AM
sudo, or not sudo: that is the question iBot UNIX and Linux RSS News 1 02-07-2008 09:40 AM
Sudo question Katkota UNIX for Dummies Questions & Answers 10 01-18-2008 01:35 AM
SUDO question - please help sajjad02 UNIX for Advanced & Expert Users 5 04-27-2005 08:22 AM
sudo question TRUEST UNIX for Dummies Questions & Answers 1 01-16-2004 08:53 PM

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 01-16-2008
Registered User
 

Join Date: May 2004
Location: Brazil
Posts: 40
Sudo question

Hello, I would like to know what should I put on the sudoers file to block a determined group os using just one specific command as root?
He can do anything, but not execute program X, how can I do this?

Thank you very much.
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 01-17-2008
RTM's Avatar
RTM RTM is offline
Hog Hunter
 
Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
By using the ! and the program you don't want to run...BUT,

Quote:
It is generally not effective to ``subtract'' commands from ALL using the '!' operator. A user can trivially circumvent this by copying the desired command to a different name and then executing that. For example:

bill ALL = ALL, !SU, !SHELLS

Doesn't really prevent bill from running the commands listed in SU or SHELLS since he can simply copy those commands to a different name, or use a shell escape from an editor or other program. Therefore, these kind of restrictions should be considered advisory at best (and reinforced by policy).
Suggest you look at the options available and do it a different way.
sudoers manual
Reply With Quote
  #3 (permalink)  
Old 01-22-2008
Registered User
 

Join Date: May 2004
Location: Brazil
Posts: 40
Thank you very much.
Reply With Quote
Google UNIX.COM
Reply

Thread Tools
Display Modes




All times are GMT -7. The time now is 11:00 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0