[sudo-users] --with-noexec option

zsilva at br.ibm.com zsilva at br.ibm.com
Wed Sep 22 21:47:05 EDT 2010


Todd ,

First thanks for your return ! 

There is no file error but is not blocking SHELLESCAPE, see exemple below 
: 

-> NOEXEC is funcional

$ sudo vi

~
~
~
:shell
No /usr/bin/ksh!

~
~
~
~
~
~
~
~

:q!

$ id
uid=39575(zsilva) gid=1(staff)
$ oslevel -s
5300-11-03-1013
$



========================================
-> NOEXEC is not funcional

servidor[/home/zsilva] sudo vi
~
~
:shell
servidor[/home/zsilva] id
uid=0(root) gid=0(system)
servidor[/home/zsilva]oslevel -s
5300-11-03-1013
servidor[/home/zsilva]


Thanks in advanced,

-  Ziner



From:
"Todd C. Miller" <Todd.Miller at courtesan.com>
To:
Zinerleme Rodrigues da Silva/Brazil/IBM at IBMBR
Cc:
sudo-users at sudo.ws
Date:
22/09/2010 10:45
Subject:
Re: [sudo-users] --with-noexec option



>From what I can see the working vs. non-working installations appear
to be identical.  Does sudo on the non-working machine give an error
when you try to use noexec or does it just fail to prevent execution?

 - todd





More information about the sudo-users mailing list