Re: [users]Re: Linux Vs Windows in security (II)



NO - You can't change the root password if you don't know the root
password. You CAN however, IF you DO.
Well, either you or me are mistaken.
'cause anyone who has access to sudo, can change the root pass, EVEN without knowing it.

You are right. root can change any password, including its own, without
having to provide the old password.

Some sites don't let sudo run passwd for that reason, but there are
dozens of ways round that. You can't block every editor either, there
are too many of them.

The cure is old-fashioned - give specific sudo access to specific users
or groups for specific programs, only as needed and make the default
sudo access nothing. Don't provide sudo access to anything that could
conceivably be used to escalate privileges - that means anything that
can modify a user-specified file on disk. And keep the members of admin
to a minimum - ideally just one.

Regards, K.

--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Karl Auer (kauer@xxxxxxxxxxxxxx) +61-2-64957160 (h)
http://www.biplane.com.au/~kauer/ +61-428-957160 (mob)


--
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-users



Relevant Pages

  • Re: Card Reader
    ... Running your script ... instead of sudo is worthless because your script *can't do ... And of course it doesn't ask for a root password, ... >> That's just more bullshit Bryan, and you might as well leave ...
    (rec.photo.digital)
  • Re: hi all..
    ... And with sudo, I certainly wouldn't because they already have root. ... If you somehow had access to my account right now, ... install an effective key logger without root. ...
    (Fedora)
  • Re: hi all..
    ... compromise security to achieve it - such as very insecure sudo defaults ... that essentially make any admin group user password a root password. ... IE someone gets your user account password, they can do more than just ...
    (Fedora)
  • Re: [kde-linux] KDE 4 and monitor powering off.
    ... konsole" entry, should run it as the same user (the "terminal" entry ... I changed it so that it would run as root since I have to ... I have sudo configured so my normal user has very limited access (some ... The admin user has full passwordless access to do everything root could ...
    (KDE)
  • Re: Choosing a distribution
    ... 'sudo bash' where I haven't had a proper root account to work with. ... cracked and hence give the intruder root access. ...
    (Ubuntu)