Re: su or sudo su?



On Tue, Oct 19, 2010 at 9:49 AM, James Mckenzie
<jjmckenzie51@xxxxxxxxxxxxx> wrote:
Tomas Hajek <thajek@xxxxxxxxxxxxx> wrote:


I have to disagree with "sudo su - is stupid."


Given all of the information in this thread and rethinking my position, I have to agree.
You can block this if needed in the sudoers file.
 Thus a user with sudo privileges could (in theory) be denied the ability to run su.

If a user can sudo to root, he/she can run su, at the very least
through the "-i" and "-s" options.


There are somethings in UNIXy systems that can only be done from console and as root.

I've never tried disabling root in Fedora, but you're logged in as
root in recovery mode in Ubuntu (and Debian if you disable root) - so
you can be root at the console through sudo or runlevel S without
having an explicit root login.
--
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines



Relevant Pages

  • Re: /etc/passwd related problem; blocked system-account
    ... The "operator"-user is allowed to use 'sudo' to do ... The theory is that as 'su' is run as "root", ... See the sudoers man page for the details on how to write a sudoers file. ... # Uncomment to allow people in group wheel to run all commands ...
    (comp.unix.bsd.freebsd.misc)
  • Re: hi all..
    ... And with sudo, I certainly wouldn't because they already have root. ... If you somehow had access to my account right now, ... install an effective key logger without root. ...
    (Fedora)
  • Re: Card Reader
    ... Running your script ... instead of sudo is worthless because your script *can't do ... And of course it doesn't ask for a root password, ... >> That's just more bullshit Bryan, and you might as well leave ...
    (rec.photo.digital)
  • Re: user login question (summary)
    ... Root can still su, because su is different from sudo: ... I also have an entry in my sudoers file for root: ... his effective user id (using su command). ...
    (SunManagers)
  • Re: root in FC 10
    ... but then the install doesn't add the one user it ... root passwd when I tried that, but no root passwd had been set ... was that user, and used that users passwd was "not in sudoers file, ... You'd get that message from sudo, ...
    (Fedora)