LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-12-2005, 08:36 AM   #1
pazvant
Member
 
Registered: Jul 2003
Location: Istanbul
Distribution: slack
Posts: 43

Rep: Reputation: 15
root access


Hi,

We have 4 root users on one linux system.We wish one root user to prevent access syslog.conf file ? So we manage this by defaut or is it possible to patch kernel by lids or gresec ..etc..

Thankx
 
Old 03-12-2005, 08:59 AM   #2
frob23
Senior Member
 
Registered: Jan 2004
Location: Roughly 29.467N / 81.206W
Distribution: OpenBSD, Debian, FreeBSD
Posts: 1,450

Rep: Reputation: 48
An interesting thing since we are dealing with a "root" user is that they will be able to override anything we do.

There are ways to do this with single users but I doubt we can get it done with "root."

Maybe if you defined what you meant by root users... are they all "root" or do they just have rootly powers?
 
Old 03-12-2005, 09:22 AM   #3
chbin
Member
 
Registered: Mar 2005
Distribution: slackware-current
Posts: 379

Rep: Reputation: 31
An interesting thing since we are dealing with a "root" user is that they will be able to override anything we do.

Absolutelly true, kind of a interesting thing to do. Kind of like a power user in windows xp, which in my opinion is not a good idea by microsoft. linux uses the keep it simple method while microsoft uses some crazy ass skem with their ownership arch. it is ridiculously complicated and you need a PH. D and a ridiculous amount of time to set ownership in any meanifull way. The most secure skem is a simple one, the more complicated it gets the less secure it gets!
 
Old 03-12-2005, 09:31 AM   #4
frob23
Senior Member
 
Registered: Jan 2004
Location: Roughly 29.467N / 81.206W
Distribution: OpenBSD, Debian, FreeBSD
Posts: 1,450

Rep: Reputation: 48
Usually, in a situation like this, you really should be using sudo (to better define access rights and log actions) as well as reconsidering the idea of offering rootly powers to someone you worry about needing to restrict.

If you can't trust these people to behave than you really need to carefully define what they should be doing and permit only those actions in sudo. Of course, you need to keep in mind that many things have "outs" which will allow them to break the sudo thing (if you give them vi they can open a root shell for example).
 
Old 03-12-2005, 09:41 AM   #5
chbin
Member
 
Registered: Mar 2005
Distribution: slackware-current
Posts: 379

Rep: Reputation: 31
perhaps one way is to change the group of syslog.conf,chown, and chgrp and only add the 3 roots to it and not the last. Of course you would really have to keep going with that idea as root4 will still have loop holes to change the group of the files back to him back to him. You would really have to think of them all and lock him out, very hard and complicated.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to get root access?? anjum Ubuntu 7 08-09-2005 10:47 AM
need help with root access gue_andy Linux - Software 1 02-07-2005 11:47 AM
Root Access Obie Linux - Security 25 06-07-2004 11:03 AM
getting access to the root deathmonkey Linux - Software 6 09-10-2003 12:27 AM
Root don't have access Rabbit Linux - Hardware 2 10-03-2002 04:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:04 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration