Offtopic

Larry Sica lomion at mac.com
Thu Apr 3 19:17:47 PST 2003


On Wednesday, April 2, 2003, at 06:01 PM, Bob Bomar wrote:

> On Tue, Mar 18, 2003 at 01:20:27PM -0600, Fabio Miranda Hamburger 
> wrote:
>> Hi, I have a couple of question:
>>
>> 1. A technique for an intruder to keep a root account was creating a 
>> stuid
>> root shell, that is not possible on FreeBSD nowadays, Why is not 
>> possible?
>> How a program like sudo can do that? Foe example, If i am a sudo 'full
>> admin' I can do this without passwd:
>> %sudo su
>> #
>
> sudo executes the command as root, and since the systems sees su
> being executed as root, you wont need that password.
>

Also it depends on how sudo is setup.  If passwords are enabled you'd 
have to enter your password.

--Larry



More information about the freebsd-chat mailing list