6 ms·
For the binary "trusted or not" scenario can't you just have sudo-to-root? That tracks each user's actions (if they don't sudo -s) and gives the trusted/entrust
by jbert 15y ago
For the binary "trusted or not" scenario can't you just have sudo-to-root? That tracks each user's actions (if they don't sudo -s) and gives the trusted/entrusted split. (bob can sudo but WWW-data can't).
- dfc 15y ago"That tracks each user's actions (if they don't sudo -s)" Or any of a million other ways: $ sudo /bin/bash $ sudo su $ cp /bin/bash ./; sudo chmod u+S ./bash; ./bash $ sudo less # invoke /bin/bash from inside less That list can keep going for a long time. Hardly a trusted way to track a user...
- zobzu 15y agoYou can track a user on Linux (reliably) Here's 2 ways I know of: - Linux Audit. Just have auditd tracing all execves. All execs made after UID transision (sudo su, sudo -s, what not) have a AUID appended that is filled with the original "logged-in-as" UID. - RSBAC. Does basically the same thing Both are kernel side. Userspace tools to control.
- dfc 15y ago"- RSBAC. Does basically the same thing" And a nuclear reactor does basically the same thing as my electric tea kettle;)
- macavity23 15y agoThe bash shell, as of v4.1, can syslog every command, if you enable it at compile time. Very useful, we use it on all our prod boxes. Take all the other shells off the system and it becomes much harder for a hax0r not to leave an audit trail.
- dfc 15y agoBecause uploading a precompiled binary is so difficult?
- bostonvaulter2 15y agoIt would at least be useful for auditing normal users of the system.
- deleted 15y ago[deleted]
- jbert 15y agoWhat I meant was that your group needs to have one "social" rule, "run all admin cmds under sudo, don't spawn a root shell and do it all there", for you to have effective tracking.
- deleted 15y ago[deleted]