1 |
On 10/26/22 3:48 PM, Ramon Fischer wrote: |
2 |
> I have created an issue at their Git repository. Maybe there will be |
3 |
> solution for this: |
4 |
> |
5 |
> https://github.com/sudo-project/sudo/issues/190 |
6 |
|
7 |
I ... don't know where to begin. |
8 |
|
9 |
There are so many ways that you can hurt yourself with syntactically |
10 |
valid sudoers that it's not even funny. |
11 |
|
12 |
You could allow list almost all commands, without using the special ALL |
13 |
place holder and then remark critical commands and end up in a very |
14 |
similar situation. |
15 |
|
16 |
At some point we have to trust that Systems Administrators / Sudoers |
17 |
editors know what they are doing and let them do so. |
18 |
|
19 |
|
20 |
|
21 |
-- |
22 |
Grant. . . . |
23 |
unix || die |