如何使用 visudo 删除重新启动、停止和关闭权限?

Car*_*ina 3 linux rhel sudo

我正在尝试剥夺用户 Rick 的重新启动权限。我已经尝试过!和NOEXEC。还有其他方法可以做到这一点吗?

Rick   ALL = (ALL)  !/sbin/reboot
Rick   ALL = NOEXEC: /sbin/reboot
Run Code Online (Sandbox Code Playgroud)

dr_*_*dr_ 6

你不能。实际上不可能创建“负 sudo”来为用户分配运行除某些命令之外的任何命令的权限。这是因为用户可以轻松绕过这些限制,例如

\n
    \n
  • 通过将被拒绝的命令插入 shell 脚本并运行它
  • \n
  • 通过将拒绝的命令复制到不同的名称
  • \n
  • 通过运行类似的命令(在您的情况下init 6,telinit 6、shutdown -r now和systemctl isolate reboot.target都将执行重新启动并且不会拒绝命令)
  • \n
  • 通过运行被拒绝的命令exec
  • \n
  • 通过从文本编辑器或其他程序中转义 shell
  • \n
  • 或者简单地通过切换到 root 用户su
  • \n
\n

联机帮助页中也提到了这一点sudoers:

\n
SECURITY NOTES\n   Limitations of the \xe2\x80\x98!\xe2\x80\x99 operator\n     It is generally not effective to \xe2\x80\x9csubtract\xe2\x80\x9d commands from ALL \n     using the \xe2\x80\x98!\xe2\x80\x99 operator.  A user can trivially circumvent this by copy-\n     ing the desired command to a different name and then executing that.  \n     For example:\n\n     bill    ALL = ALL, !SU, !SHELLS\n\n     Doesn\xe2\x80\x99t really prevent bill from running the commands listed in SU\n     or SHELLS since he can simply copy those commands to a different\n     name, or use a shell escape from an editor or other program.  \n     Therefore, these kind of restrictions should be considered advisory at\n     best (and reinforced by policy).\n\n     In general, if a user has sudo ALL there is nothing to prevent \n     them from creating their own program that gives them a root shell (or\n     making their own copy of a shell) regardless of any \xe2\x80\x98!\xe2\x80\x99 elements \n     in the user specification.\n
Run Code Online (Sandbox Code Playgroud)\n

相反,您应该确定用户所需的一组受限命令,并仅授予对这些命令的访问权限。

\n

NOEXEC只是禁用 shell 转义,并不能防止所有其他规避方法。

\n

  • 如果根本没有“sudo”,用户仍然拥有一个简单但不优雅的硬件解决方案,因此软件控制不会非常有效。根本问题的真正解决方案可能是workplace.se 或interpersonal.se 的问题。 (3认同)