[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: sudo and UNIXes (was: audacity export wma format[1 more question])



 Hi.

On Sat, 26 Oct 2013 21:50:23 +0000
Tom H <tomh0665@gmail.com> wrote:

> On Fri, Oct 25, 2013 at 9:16 PM, Reco <recoverym4n@gmail.com> wrote:
> 
> 
> > Yes, but pfexec is not sudo. And privilege-aware Solaris shells are
> > definitely not sudo too.
> 
> It might not be sudo but it's the same principle of privilege escalation.
> 
> sudo's simpler to set up so I've yet to work at any Solaris shop where
> it hasn't been installed (it's not necessarily used though; I
> moonlight at two companies where telnetting as root is the norm...).

I agree that sudo is simpler to setup. I disagree that sudo is
installed everywhere where Solaris is.
Because - it's third-party software. And people don't like to install
third-party software ('vendor didn't included it - we don't use it').
As for telnet as a root - the very setup of Solaris (before 10u4 iirc),
pushed one to do exactly this (ssh required manual generation of host
keys, telnet was already there and worked, root is the only working
user after install).


> >>> Considering that primary usage of sudo is to provide controlled
> >>> privilege escalation to uid=0, using unsupported (therefore - not
> >>> updated unless local sysadmins care about security) sudo on these OSes
> >>> is basically equivalent to giving everyone uid=0.
> >>
> >> Somewhat exaggerated :)
> >
> > No offense meant, but probably you're living in a some kind of IT
> > paradise ;) 'Nobody does no evil, nobody does any mistakes' kind of
> > paradise.
> 
> Not updating/patching sudo isn't equivalent to giving everyone root
> access! It's a BIG leap!

True, you need to add to the picture that curious user who just read on
Bugtraq or Full Disclosure about fresh vulnerability in sudo. Or that
disgruntled user who needs /etc/system changed right here and now. Or
that developer who needs to do this 'small change, nobody will notice'
on a production server.
And if you don't have such people there - good for you, as here we can
always find such person here.

Reco


Reply to: