04-18-2008
Maybe I haven't defined by question correctly.
What I want to stop is a user elevating to root via the following:
sudo bash.
This is easy enough to do via a sudoers restriction on running the command.
Now, I have a group of admins that need to be able to run most system commands. However, I want to be able to log all commands they run as root, for auditing purposes. So I use sudo.log.
The user bypasses sudo logging if they execute su or a shell via sudo. As mentioned above, I can prevent this by explicitly denying the commands in sudoers file.
However, if the user (or admin) copies a shell (say /usr/bin/bash, but could be any shell) to another location/name (could be any location or name), what's to stop them now executing this renamed and relocated shell command via sudo, which in effect, gives them root access without sudo.log logging.
Please don't get hung up on homedir being the location - it could be any directory with write and execute permissions.
So, is it possible on your system for a user to copy(rename) a shell command to another location and then execute it via sudo?
If not, why not?
This is what I want to prevent.
9 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
how do i go about adding a file to sudo so a user name oracle can run the file???
for some reason my man pages dont have anything for sudo.
files sudoers exist in /etc
can anyone help this is urgent
thank you (1 Reply)
Discussion started by: TRUEST
1 Replies
2. UNIX for Advanced & Expert Users
Hi, I was wondering if someone can give me some pointers about configuring SUDO. I am trying to configure SUDO to have about 30 users run about 200 scripts as a different user. I understand that I can create an User_Alias but how do I give that User_Alias rights to run all the scripts in a certain... (5 Replies)
Discussion started by: sajjad02
5 Replies
3. UNIX for Dummies Questions & Answers
Folks;
I have a sudo question:
- I have a real user named "greg" and another generic user named "devuser" & application that must be run like start/stop as "devuser" user.
Is there a way to:
Have user Greg login into the Solaris 10 box as himself then sudo as "devuser" to be able to... (10 Replies)
Discussion started by: Katkota
10 Replies
4. Linux
Hello, I would like to know what should I put on the sudoers file to block a determined group os using just one specific command as root?
He can do anything, but not execute program X, how can I do this?
Thank you very much. (2 Replies)
Discussion started by: Zarnick
2 Replies
5. Ubuntu
Hello all,
Anyone fimilar with su -l command?
So when I do su -l <user> any user it doesn't prompt me for password for that user. How I enable sudo to prompt for password whenever su -l command is used.
Please help!
thanks,
-Lalit
:D (7 Replies)
Discussion started by: email-lalit
7 Replies
6. UNIX for Dummies Questions & Answers
Folks;
I have SUDO configured on my SUSE boxes to allow a specific groups to run specific duties so one group has ALL permission & other group has permission to run a few commands only.
when i look at the sudoer log, i see people login info only,
Is there a way to capture every thing users do... (3 Replies)
Discussion started by: Katkota
3 Replies
7. UNIX for Dummies Questions & Answers
Hello all,
I have a script (script.sh) that is owned and executed by root. Now I need to give another user (user1) sudo access to execute that script.
I edited the /etc/sudoers file, and created the following:
# Runas alias specification
Runas_Alias RO = root
user1 ALL=(RO)... (1 Reply)
Discussion started by: designbc
1 Replies
8. UNIX for Advanced & Expert Users
Hi All
I want to grant elevated privs to a user that will be running a script as a background task. It will be launched from an ssh session via an embedded command in its key that just allows that account to run that script.
I'm reading up on sudo and notice that -
user ALL=(ALL) ALL
... (2 Replies)
Discussion started by: steadyonabix
2 Replies
9. AIX
I am running AIX 6.6.5.115 and am experiencing a problem using sudo. I have shell scripts that I created for our HR user and shell scripts that I created for root administrators. I do have a need to embed a sudo command in the user shell script to run one command as root. However the two... (8 Replies)
Discussion started by: RonDeF
8 Replies
LEARN ABOUT OSX
heimdal_debug
heimdal_debug(5) BSD File Formats Manual heimdal_debug(5)
NAME
heimdal_debug -- how to turn on/off debugging for Kerberos tools
DESCRIPTION
The heimdal_debug kerberos frameworks have several knobs for controlling logging. The different framework knobs are:
libkrb
The Kerberos library, some gss-api Kerberos output ends up here too
kcm the kcm library (credentials cache, ntlm client)
kdc the kerberos KDC output
digest-service
the digest service (ntlm server)
CONFIGURATION FILE
[logging]
<subsystem> = 0-/SYSLOG:
and watch syslog for logging information.
APPLE MAC OS X
First turn up syslog debugging
sudo syslog -c 0 -d
then you can see the syslog output in Console.app or by running
syslog -w -k org.h5l.asl
To enable more extensive debugging logging for each subsystem, use the following commands:
Kerberos Library
sudo defaults write /Library/Preferences/com.apple.Kerberos logging -dict-add krb5 '0-/ASL:'
digest-server
sudo defaults write /Library/Preferences/com.apple.Kerberos logging -dict-add digest-service '0-/ASL:'
kcm sudo defaults write /Library/Preferences/com.apple.Kerberos logging -dict-add kcm '0-/ASL:'
kdc sudo defaults write /Library/Preferences/com.apple.Kerberos logging -dict-add kdc '0-/ASL:'
MIT Kerberos Shim
defaults write com.apple.MITKerberosShim EnableDebugging -bool true
GSS-API framework logging
sudo defaults write /Library/Preferences/com.apple.GSS DebugLevel -int 10
Other options on Mac OS X
Make the admin API pretend to the server even on client
sudo defaults write /Library/Preferences/com.apple.Kerberos ForceHeimODServerMode -bool true
SEE ALSO
gss(5), kerberos(8)
HEIMDAL
Sep 30, 2011 HEIMDAL