[sudo-users] Restricting / Limiting permission/ownership of targetted binaries?

Mihai Moldovan ionic at ionic.de
Fri Apr 30 03:29:08 MDT 2021


* On 4/30/21 11:15 AM, L A Walsh wrote:
> If someone can change permissions on sudo,

You have misunderstood the issue at hand.

It's not about the permissions of the sudo binary, but about the permissions of
the target binary that is to be executed.


AFAIK, there is no such built-in functionality.

This sounds like a prime example of functionality that could be implemented as a
plugin, though.



Mihai

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <http://www.sudo.ws/pipermail/sudo-users/attachments/20210430/e86c89a5/attachment.bin>


More information about the sudo-users mailing list