The Daily Static
  The Daily Static
UF Archives
Register
UF Membership
Ad Free Site
Postcards
Community

Geekfinder
UFie Gear
Advertise on UF

Forum Rules
& FAQ


Username

Password


Create a New Account

 
 

Back to UserFriendly Strip Comments Index

Major Linux Help Please! by MatthewDBA2006-09-07 13:43:15
  Log in as a regular user, then su by Stuka2006-09-07 13:48:10
    note the user has to be in the "wheel" group by Freakazoid2006-09-07 15:45:49
      I thought that was only on gentoo? by Sharku2006-09-07 15:48:19
        it's like that on all distros by Freakazoid2006-09-07 15:49:36
          Um, no, it's not. by bwkaz 2006-09-07 16:17:42
LFS (which isn't actually a distro in the traditional sense, but is the basis for a lot of "one-off" distros) just compiles shadow and leaves most settings in shadow's /etc/login.defs file at their defaults. (It does not install PAM, though it does mention that if you plan on using PAM, you should go install it before installing shadow.)

Anyway, shadow's /etc/login.defs file has a parameter in it for whether /bin/su will allow users who are not members of the wheel group have access to UID 0 -- and it's off by default (so by default, everyone can su to root). ("The wheel group" is documented to be the first group in /etc/groups that has GID 0.) The permissions on /bin/su are also 4755, so all users can execute it.

(There's at least one LFS hint that mentions changing /bin/su so that its GID is some trusted group, and removing world-read and world-execute permission. Then only members of that trusted group -- and root -- can change to *any* different user. But again, it's not the default.)
[ Reply ]

 

[Todays Cartoon Discussion] [News Index]

Come get yer ARS (Account Registration System) Source Code here!
All images, characters, content and text are copyrighted and trademarks of J.D. Frazer except where other ownership applies. Don't do bad things, we have lawyers.
UserFriendly.Org and its operators are not liable for comments or content posted by its visitors, and will cheerfully assist the lawful authorities in hunting down script-kiddies, spammers and other net scum. And if you're really bad, we'll call your mom. (We're not kidding, we've done it before.)