Can we please stop talking about that sudo bug? It only affects systems using an insane configuration (allow $command as anyone *but* root). I can't come up with any situation where that configuration makes any sense (vs e.g. "allow $command as any member of a given group).
It's an example, I'm sure you can find your own root-equivalent user on your system if you go looking.
-
-
nope. this is typically added by certain distros; it's not universal. [bts@cylon ~]$ grep disk /etc/group disk:x:6:root [bts@cylon ~]$ grep disk /etc/passwd [bts@cylon ~]$
-
There are other escalation paths besides raw disk access. And, since enumerating them is problematic, any sudoers config that grants sudo to all users but root is vulnerable unless proven otherwise, and should never be used.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.