Security Basics mailing list archives
Re: How to track down which commands sudoers set up?
From: Michael Rice <michael () riceclan org>
Date: Tue, 13 Jun 2006 15:11:27 -0500
I'd like to find out what exactly any user did after they turned to superuserand when exactly each cmd was processed (in a Linux box). Can someone help me managing this?
Others have already extolled the virtues of sudo and why to use it over su. For myself, I use a facility based on 'script' to further enhance sudo -- when our users feel required to be in a root shell I have a process that they can use to provide me with a log of their session.
There was a very similar project called sudosh that could be found on sourceforge. Either of these, like sudo, provides auditability if you set it up ahead of time, but doesn't really protect you from the malicious and clever user who can use it to modify their own logs.
An interesting new project from the sudosh author is EAS (http://eas.strchr.net/). I haven't used it yet, but it looks promising to fill the niche sudo leaves.
Current thread:
- How to track down which commands sudoers set up? Jannis Kafkoulas (Jun 13)
- Re: How to track down which commands sudoers set up? James Harless (Jun 13)
- Re: How to track down which commands sudoers set up? Erin Carroll (Jun 14)
- Re: How to track down which commands sudoers set up? Isaac Perez (Jun 13)
- Re: How to track down which commands sudoers set up? Sergio Guzman Lorz (Jun 14)
- Re: How to track down which commands sudoers set up? Peter Morgan (Jun 13)
- Message not available
- Fwd: How to track down which commands sudoers set up? Stuart Howard (Jun 14)
- Message not available
- Re: How to track down which commands sudoers set up? Michael Rice (Jun 14)
- Re: How to track down which commands sudoers set up? James Harless (Jun 13)
- Re: How to track down which commands sudoers set up? Huzeyfe Onal (Jun 14)
- Re: How to track down which commands sudoers set up? jm (Jun 14)
- Re: How to track down which commands sudoers set up? ascii (Jun 14)
- Re: How to track down which commands sudoers set up? Joe Hood (Jun 14)