1 |
On Wed, 26 Oct 2022 20:04:10 +0200, Ramon Fischer wrote: |
2 |
|
3 |
> Also a very interesting question! |
4 |
> |
5 |
> I just tested this with "visudo" and it does not intercept this. |
6 |
> |
7 |
> If "su" is disabled, you are locked out and you are forced to enter |
8 |
> your system via a live USB stick and a "chroot" in order to edit |
9 |
> "/etc/shadow" to set a root password via "mkpasswd" and enable "su". |
10 |
> Nice. :D |
11 |
|
12 |
You need to be root to write to /etc/sudoers.d. If someone has that |
13 |
access, you are already doomed! |
14 |
|
15 |
> |
16 |
> -Ramon |
17 |
> |
18 |
> On 26/10/2022 18:52, Grant Taylor wrote: |
19 |
> > What if someone were to put the following into |
20 |
> > /etc/sudoers.d/zzzzzzzzzz |
21 |
> > |
22 |
> > ALL ALL=(ALL) !ALL |
23 |
> > |
24 |
> > }:-) |
25 |
|
26 |
|
27 |
|
28 |
|
29 |
-- |
30 |
Neil Bothwick |
31 |
|
32 |
I thought I saw the light at the end of the tunnel... |
33 |
but it was just some sod with a torch bringing me more work! |