Can we please stop talking about that sudo bug? It only affects systems using an insane configuration (allow $command as anyone *but* root). I can't come up with any situation where that configuration makes any sense (vs e.g. "allow $command as any member of a given group).
-
-
So if there are people there who actually had the sample config in the vuln report, they are vulnerable to all hell and back *anyway*, and if they've been trying to play whack-a-mole by excluding all "root-equivalent" user accounts, that's a ridiculous idea and they'll miss one.
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
this assumes there an adm user. [bts@cylon ~]$ grep adm /etc/passwd [bts@cylon ~]$
-
It's an example, I'm sure you can find your own root-equivalent user on your system if you go looking.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.