ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Sudoers vulnerability found

    Scheduled Pinned Locked Moved IT Discussion
    8 Posts 5 Posters 578 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403
      last edited by

      Here is the brief.

      1 Reply Last reply Reply Quote 1
      • stacksofplatesS
        stacksofplates
        last edited by

        That's why best practice is to mount tmp and other file systems that don't contain /dev with nodev. That way someone can't create a fake device.

        1 Reply Last reply Reply Quote 0
        • ObsolesceO
          Obsolesce
          last edited by

          Better switch to Windows!

          DustinB3403D 1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403 @Obsolesce
            last edited by

            @Tim_G said in Sudoers vulnerability found:

            Better switch to Windows!

            Ha. . .

            1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch
              last edited by

              I swear we talked about this a week ago.

              DustinB3403D 1 Reply Last reply Reply Quote 0
              • DustinB3403D
                DustinB3403 @JaredBusch
                last edited by

                @JaredBusch said in Sudoers vulnerability found:

                I swear we talked about this a week ago.

                Was it? I may have missed it. If I did, a reminder doesn't hurt.

                1 Reply Last reply Reply Quote 0
                • coliverC
                  coliver
                  last edited by

                  We talked about a similar issue last week. I don't think it was this exact vulnerability... Just like the previous one though this is more of the "If you configure a system incorrectly and give someone sudo access you're going to have a bad day." types of error rather then a full blown security issue.

                  JaredBuschJ 1 Reply Last reply Reply Quote 1
                  • JaredBuschJ
                    JaredBusch @coliver
                    last edited by

                    @coliver said in Sudoers vulnerability found:

                    We talked about a similar issue last week. I don't think it was this exact vulnerability... Just like the previous one though this is more of the "If you configure a system incorrectly and give someone sudo access you're going to have a bad day." types of error rather then a full blown security issue.

                    Ah, ok. But yeah, if you give someone sudo, you are already trusting them to not fuck up your system.

                    1 Reply Last reply Reply Quote 4
                    • 1 / 1
                    • First post
                      Last post