LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-19-2005, 10:51 AM   #1
satinet
Senior Member
 
Registered: Feb 2004
Location: England
Distribution: Slackware 14.2
Posts: 1,492

Rep: Reputation: 50
sudo logging


Hello,

I am setting up sudo on a server. It's working very smoothly so far. I'm still in the testing phase. When try to 'sudo' a command that the user is not authorised to run, the warning goes to a log file. However, it also echos to the root user's tty, which is really really not what i want to happen.

Here is my /etc/sudoers file:
Code:
Defaults        logfile=/var/run/sudo/sudo.log, mailto="admin@domain.com" 
Cmnd_Alias   ADDUSER=/ops/adduser

# User privilege specification
root    ALL=(ALL) ALL

# Members of the admin group may gain root privileges
%sdesk ALL=NOPASSWD:/sbin/passwd,ADDUSER

Can anyone give me any hints?

Many thanks.

Tom
 
Old 10-20-2005, 11:04 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,417
Blog Entries: 55

Rep: Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627
However, it also echos to the root user's tty, which is really really not what i want to happen.
dmesg -n[number]?
 
Old 10-21-2005, 02:51 AM   #3
satinet
Senior Member
 
Registered: Feb 2004
Location: England
Distribution: Slackware 14.2
Posts: 1,492

Original Poster
Rep: Reputation: 50
thanks for you tip.

however, the problem is that a failure event is treated as an 'event'. if you see below this kind of event gets echoed to root's terminal because of how i have /etc/syslog.conf set up.

from http://www.courtesan.com/sudo/man/sudoers.html#defaults

syslog_badpri
Syslog priority to use when user authenticates unsuccessfully. Defaults to alert.

# @(#)B.11.11_LR
#
# syslogd configuration file.
#
# See syslogd(1M) for information about the format of this file.
#
mail.debug /var/adm/syslog/mail.log
*.info;mail.none /var/adm/syslog/syslog.log
*.alert /dev/console
*.alert root
*.emerg *
 
Old 10-21-2005, 04:37 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,417
Blog Entries: 55

Rep: Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627Reputation: 3627
if you see below this kind of event gets echoed to root's terminal because of how i have /etc/syslog.conf set up.
Yeah, that would have been my second guess.

It's all going to file, which should mean you're using some reporting tool to filter the logs and send alerts to people, so why not disable the console line? No one should be on the root console all the time anyway.
 
Old 10-21-2005, 05:56 AM   #5
satinet
Senior Member
 
Registered: Feb 2004
Location: England
Distribution: Slackware 14.2
Posts: 1,492

Original Poster
Rep: Reputation: 50
yeah, it was my own over exurberance.

Well, it's hp-ux - i've got no real alternative to logging in as root using telnet (!). The app we run can't even use shadow passwords! haha.

Anyway, i think i acutally want to know if someone manages to do a wrong sudo, as no one actually has access to the terminal.

we don't use a reporting tool as such. Thanks for your input.

FYI this is run from a menu within a FAT client. the service desk will be creating using accounts..... lol... melt down time.......
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Restricting Editing in Sudo (Advanced Sudo Question) LinuxGeek Linux - Software 4 11-04-2006 03:20 PM
su and sudo muman Linux - Security 9 12-30-2004 10:55 AM
correct sudo logging in RedHat sancho5 Linux - General 1 05-07-2004 08:52 AM
using red-carpet without logging out and logging as root. packman Linux - Software 1 12-09-2002 02:55 AM
sudo? nabil Linux - Security 1 02-12-2001 01:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:35 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration