我正在尝试剥夺用户 Rick 的重新启动权限。我已经尝试过!和NOEXEC。还有其他方法可以做到这一点吗?
Rick ALL = (ALL) !/sbin/reboot
Rick ALL = NOEXEC: /sbin/reboot
Run Code Online (Sandbox Code Playgroud)
你不能。实际上不可能创建“负 sudo”来为用户分配运行除某些命令之外的任何命令的权限。这是因为用户可以轻松绕过这些限制,例如
\ninit 6,telinit 6、shutdown -r now和systemctl isolate reboot.target都将执行重新启动并且不会拒绝命令)execsu联机帮助页中也提到了这一点sudoers:
SECURITY NOTES\n Limitations of the \xe2\x80\x98!\xe2\x80\x99 operator\n It is generally not effective to \xe2\x80\x9csubtract\xe2\x80\x9d commands from ALL \n using the \xe2\x80\x98!\xe2\x80\x99 operator. A user can trivially circumvent this by copy-\n ing the desired command to a different name and then executing that. \n For example:\n\n bill ALL = ALL, !SU, !SHELLS\n\n Doesn\xe2\x80\x99t really prevent bill from running the commands listed in SU\n or SHELLS since he can simply copy those commands to a different\n name, or use a shell escape from an editor or other program. \n Therefore, these kind of restrictions should be considered advisory at\n best (and reinforced by policy).\n\n In general, if a user has sudo ALL there is nothing to prevent \n them from creating their own program that gives them a root shell (or\n making their own copy of a shell) regardless of any \xe2\x80\x98!\xe2\x80\x99 elements \n in the user specification.\nRun Code Online (Sandbox Code Playgroud)\n相反,您应该确定用户所需的一组受限命令,并仅授予对这些命令的访问权限。
\nNOEXEC只是禁用 shell 转义,并不能防止所有其他规避方法。
| 归档时间: |
|
| 查看次数: |
489 次 |
| 最近记录: |