Security Basics mailing list archives

Re: SUDO vs root account question


From: Blaine Lefler <blaine () theleflers com>
Date: Wed, 23 Mar 2005 18:49:43 -0700

Tahis
The situation that you described will allow root access. There is one other issue with sudo. Sudo will allow shell escapes. There is a whole section on the sudo page at http://www.gratisoft.us/sudo/ to help prevent this. I used to use sudo a lot at another company and it work well. Blaine


Tahis Vera wrote:
Hi all,
I have two quick questions related to the 'sudo' command;
putting a certain user Mr.X with ALL=(ALL)ALL permissions in the
sudoers file, gives him COMPLETE root previleges? In other words, if I
want that some people, for security reasons, stop using the root
account/password for accessing the servers, by crating a sudo user
with ALL previledges will decrease this risk? If this sudo account  is
compromised, will the cracker have COMPLETE root previleges?

The other questions is how to set the time (in sudoers file) for the
user to work with sudo, without having to write the password (let's
say that I want to work for 20 minutes without having to write the
password again)

regards

Tahis





Current thread: