Re: Tool of Use to Unix WebCat Admins

This WebDNA talk-list message is from

2000


It keeps the original formatting.
numero = 36035
interpreted = N
texte = On 8/9/00 1:37 PM, John Peacock at JPeacock@UnivPress.com wrote:> Sudo is a program designed to allow a sysadmin to give limited root > privileges to users and log root activity. [...]Sudo is a very handy tool but you have to be careful because it can be a security hole if you're not. For example, you don't want any of your sudoers to be able to run an editor as root, because many unix editors allow shell escapes, which would give the sudoer a root shell. Also, any sudoer has to be on guard against password compromise, more so than a regular user since anybody with their name and passowrd can do any potentially destructive activities allowed by the sudoers file. Sudo's ALL=ALL directive is particularly dangerous since it practically makes a user with that attribute root. If you use sudo (read: if you provide shells to your customers at all), urge your users to use SSH or some other crypted protocol to start a shell session and be as strict as possible in defining permissions in the sudoers file. Start out with only a few privileges at first and keep everything else clamped down, then grant privileges only as needed.Actually, it's best not to provide shell access in the first place unless it's unavoidable.-- Andrew Vernon avernon@dramatols.net------------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/ Associated Messages, from the most recent to the oldest:

    
  1. Re: Tool of Use to Unix WebCat Admins (John Peacock 2000)
  2. Re: Tool of Use to Unix WebCat Admins (Andrew Vernon 2000)
  3. Tool of Use to Unix WebCat Admins (John Peacock 2000)
  4. Tool of Use to Unix WebCat Admins (John Peacock 2000)
  5. Re: Tool of Use to Unix WebCat Admins (Dale 2000)
  6. Tool of Use to Unix WebCat Admins (John Peacock 2000)
On 8/9/00 1:37 PM, John Peacock at JPeacock@UnivPress.com wrote:> Sudo is a program designed to allow a sysadmin to give limited root > privileges to users and log root activity. [...]Sudo is a very handy tool but you have to be careful because it can be a security hole if you're not. For example, you don't want any of your sudoers to be able to run an editor as root, because many unix editors allow shell escapes, which would give the sudoer a root shell. Also, any sudoer has to be on guard against password compromise, more so than a regular user since anybody with their name and passowrd can do any potentially destructive activities allowed by the sudoers file. Sudo's ALL=ALL directive is particularly dangerous since it practically makes a user with that attribute root. If you use sudo (read: if you provide shells to your customers at all), urge your users to use SSH or some other crypted protocol to start a shell session and be as strict as possible in defining permissions in the sudoers file. Start out with only a few privileges at first and keep everything else clamped down, then grant privileges only as needed.Actually, it's best not to provide shell access in the first place unless it's unavoidable.-- Andrew Vernon avernon@dramatols.net------------------------------------------------------------- This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://search.smithmicro.com/ Andrew Vernon

DOWNLOAD WEBDNA NOW!

Top Articles:

Talk List

The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...

Related Readings:

database problem (2003) [username][password] not showing up! HELP! (1999) Automatic installation of WebDNA by hosting clients? (2005) WebCat2b14MacPlugIn - [include] doesn't hide the search string (1997) WebCat2b12 - nesting [tags] (1997) Eudora Plugin (1999) LetterRip and WebCat (1998) [WebDNA] [OT] the "Work in progress" thread. (2009) PIXO (1997) PCS Frames (1997) a little OT (2001) Mystery authentication (1997) Remote stockroom ? (1998) Tea Room trouble (1997) Re:Can this be done? (1997) Email within tmpl ? (1997) Banners (1997) searching by date (1998) Web Catalog 2 demo (1997) Listserver problem (1997)