Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: su - userid
From: crotherm @ roses . rockwell . com (Mark A. Crother)
Date: Mon, 9 Sep 1996 10:40:37 -0700 (PDT)
To: Doug . Hughes @ eng . auburn . edu (Doug Hughes)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <199609091631 . LAA14356 @ dns . eng . auburn . edu> from "Doug Hughes" at Sep 9, 96 11:31:25 am

> 
> >
> >Hi,
> > 
> >I know that this is not the right place, but thought that there must be
> >a lot of capable people who can answer this .
> > 
> >Our system administrator is not capable of distinguishing the fact of 
> >how to stop people from using some one else 's id.
> >We are running NIS+. 
> >
> >The process:
> > 
> >su - root (On any client machine, of which you have the password.)
> > 
> >Now 
> >su - userid (You get logged in as the 'userid' specified).
> 
> chmod 750 /bin/su
> chgrp staff /bin/su 
> (or use whatever group all your admin people belong to.)

That won't work because because the client's root password is 
available to those who they wish to deny su, and with root you could
just do chmod 755 /bin/su.  Or for that matter, they could do anything
they want on the client machine.

> 
> However, this won't prevent people from using telnet, or rlogin, or
> any other of myriad ways to get to another's account. The problem
> is not su, it is of people sharing passwords. This is a people
> problem and not a technical one.

Agreed!  root passwords belong only to sysadms if you wish to have a
secure network.

> 
> 
> 


-- 
Mark Crother				crotherm @
 roses .
 rockwell .
 com
Rockwell's Operational Software Engineering System (ROSES)
Space Systems Division (SSD)	All opinions are mine.


References:
Indexed By Date Previous: Re: su - userid
From: crotherm @ roses . rockwell . com (Mark A. Crother)
Next: Re: FreeBSD Firewall Package
From: Jim Lester <jim . lester @ ljo . dec . com>
Indexed By Thread Previous: Re: su - userid
From: Doug Hughes <Doug . Hughes @ Eng . Auburn . EDU>
Next: RE: su - userid
From: "L'ROY Robert (MSMail)" <RLroy @ shl . com>

Google
 
Search Internet Search www.greatcircle.com