1 |
On 2011-12-20 12:19 PM, Nikos Chantziaras <realnc@×××××.de> wrote: |
2 |
> If you allow someone to edit root owned files, you're practically giving |
3 |
> him root access. |
4 |
|
5 |
Well, yeah, but only on those defined files... |
6 |
|
7 |
I'm not worried about them messing up stuff in /var/www/*, but I am |
8 |
worried about them messing up stuff in /etc |
9 |
|
10 |
> So the fact that he doesn't know the root password is totally |
11 |
> irrelevant; he doesn't even need the password anymore to gain root |
12 |
> access since he already has that access. |
13 |
|
14 |
But he only has root access in explicitly defined, non-system, non |
15 |
critical directories... |
16 |
|
17 |
> So you might want to rethink the way you want to allow him to edit those |
18 |
> files. |
19 |
|
20 |
I *want* him to be able to do whatever he wants in /var/www (and a few |
21 |
other non critical directories)... |