LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-23-2005, 01:46 AM   #1
bax
Member
 
Registered: Dec 2001
Location: NoVA
Distribution: Ubuntu, Solaris, OpenBSD
Posts: 492

Rep: Reputation: 30
lost ability to su


In my attempts to harden a Redhat ES 3 box I ran the following commands from a Linux security book.

/bin/chgrp wheel /bin/su
/bin/chmod 4750 /bin/su

This was after I added one username to the wheel group under /etc/group Now no one can su. I'm doing all of my work at work instead of remotely trying to fix this problem. I get a "incorrect password" error for any username trying to su either to root or another user. I know the passwords are correct, I even changed one to be sure.
I changed the ownership of su back to the root group and ran chmod 0755 on the file itself. What am I missing here? ANY help/advice is appreciated.
 
Old 01-23-2005, 02:03 AM   #2
bax
Member
 
Registered: Dec 2001
Location: NoVA
Distribution: Ubuntu, Solaris, OpenBSD
Posts: 492

Original Poster
Rep: Reputation: 30
chmod 04755 fixed it. Now how can finish what I was attempting? Added the username right behind root in the wheel entry in /etc/group I was certain I'd done things right.
 
Old 01-23-2005, 12:21 PM   #3
btmiller
Senior Member
 
Registered: May 2004
Location: In the DC 'burbs
Distribution: Arch, Scientific Linux, Debian, Ubuntu
Posts: 4,290

Rep: Reputation: 378Reputation: 378Reputation: 378Reputation: 378
Did you logout and re-login the user after you had added him to the wheel group? Group membership is set at login time, so changing /etc/group while a user is logged in will have no effect on their group membership. If you don't want to logout and re-login, you can also use newgrp to become a member of a group that you've been added to.
 
Old 01-29-2005, 03:32 AM   #4
zsoltrenyi
Member
 
Registered: May 2004
Distribution: redhat, trustix, debian
Posts: 103

Rep: Reputation: 15
you want only members of group wheel to be able to su to root?
i've done this with pam once but i don't remember exactly how
you have to put something like this in /etc/pam.d/su: Auth required /lib/security/pam_wheel.so group=wheel
do a search in google for examples
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Oracle on Fedora Core 2 - User has lost X ability madfish Fedora 1 02-05-2005 02:55 PM
gerecom lost all ability to access the cdrom/dvd/cd-rw moby Linux - Laptop and Netbook 0 08-23-2004 03:15 PM
lost ability to play audio CDs synaptical Linux - Software 5 02-14-2004 05:10 PM
HELP!!!! lost ability to boot Debian Interceptor Linux - Hardware 2 05-16-2003 08:21 AM
Lost printing ability struggler Linux - Newbie 1 02-21-2002 10:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration