<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is this possible with sudo !!! in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039053#M302569</link>
    <description>entry in /etc/sudoers&lt;BR /&gt;username ALL=(ALL) NOPASSWD: ALL&lt;BR /&gt;&lt;BR /&gt;Both of the below commands work.&lt;BR /&gt;sudo su -&lt;BR /&gt;sudo su - root&lt;BR /&gt;&lt;BR /&gt;$ sudo su - root -c /home/kumarts/ebrdo0pb_dgfiles&lt;BR /&gt;You have mail.&lt;BR /&gt;sh: /home/kumarts/ebrdo0pb_dgfiles:  not found.&lt;BR /&gt;logout&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Tue, 17 Jul 2007 16:05:04 GMT</pubDate>
    <dc:creator>skt_skt</dc:creator>
    <dc:date>2007-07-17T16:05:04Z</dc:date>
    <item>
      <title>Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039049#M302565</link>
      <description>Admins. please bear with this freaky qn... &lt;BR /&gt;&lt;BR /&gt;Is it possible for a normal user to run WITHOUT password the below command, who got limited sudo permission,&lt;BR /&gt;&lt;BR /&gt;sudo su - root -c &amp;lt;script&amp;gt; &lt;BR /&gt;&lt;BR /&gt;I know, instead we can just give the script in sudo for that user, to have root priviledge.. WH</description>
      <pubDate>Tue, 17 Jul 2007 15:23:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039049#M302565</guid>
      <dc:creator>Whitehorse_1</dc:creator>
      <dc:date>2007-07-17T15:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039050#M302566</link>
      <description>Allowing sudo to do su to root would bypass all logging.  You should just allow it to do that script.</description>
      <pubDate>Tue, 17 Jul 2007 15:39:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039050#M302566</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2007-07-17T15:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039051#M302567</link>
      <description>Well, if sudo were setup with this command AND /etc/sudoers allowed this user to execute su as root AND this same regular user had previously executed some sort of sudo'ed command within the timestamp_timeout period specified in the sudoers file then this invocation of sudo would not trigger a password requirement. Note that the first invocation of sudo by the user would require a password and that would create a timestamp file. Any command entered by the same user before the password timeout would not require a password.&lt;BR /&gt;&lt;BR /&gt;Now this is exactly the kind of command that you do not want sudo to do. Let sudo execute this command directly and set the effective UID.&lt;BR /&gt;&lt;BR /&gt;It would probably lead to a more straightforward solution if you explained what you are trying to do rather than asking if this Plan A, Plan B, or Plan C will work.&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Jul 2007 15:40:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039051#M302567</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2007-07-17T15:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039052#M302568</link>
      <description>No - they still need to enter their password.&lt;BR /&gt;&lt;BR /&gt;Rgds...Geoff</description>
      <pubDate>Tue, 17 Jul 2007 15:42:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039052#M302568</guid>
      <dc:creator>Geoff Wild</dc:creator>
      <dc:date>2007-07-17T15:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039053#M302569</link>
      <description>entry in /etc/sudoers&lt;BR /&gt;username ALL=(ALL) NOPASSWD: ALL&lt;BR /&gt;&lt;BR /&gt;Both of the below commands work.&lt;BR /&gt;sudo su -&lt;BR /&gt;sudo su - root&lt;BR /&gt;&lt;BR /&gt;$ sudo su - root -c /home/kumarts/ebrdo0pb_dgfiles&lt;BR /&gt;You have mail.&lt;BR /&gt;sh: /home/kumarts/ebrdo0pb_dgfiles:  not found.&lt;BR /&gt;logout&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Jul 2007 16:05:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039053#M302569</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-07-17T16:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039054#M302570</link>
      <description>&amp;gt; username ALL=(ALL) NOPASSWD: ALL&lt;BR /&gt; &lt;BR /&gt;Yes, the user can do *ANYTHING* without any additional password. So you might as well remove the password for root because there is absolutely no security now. The above construct has given keys away and your system may need a complete reinstall in a few minutes.&lt;BR /&gt; &lt;BR /&gt;sudo's design is to LIMIT the root capabilities, by command, even down to the parameters allowed for a command. ALL=(ALL) just disables all those capabilities.</description>
      <pubDate>Tue, 17 Jul 2007 19:35:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039054#M302570</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2007-07-17T19:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039055#M302571</link>
      <description>Just to remind that the user which i listed is an administrator user who can do all operation without the root password.</description>
      <pubDate>Tue, 17 Jul 2007 19:54:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039055#M302571</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-07-17T19:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039056#M302572</link>
      <description>you probably do not want to do this, or at least not in the way you described.&lt;BR /&gt;&lt;BR /&gt;better is to find another (saner) solution to your problem.</description>
      <pubDate>Wed, 18 Jul 2007 01:29:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039056#M302572</guid>
      <dc:creator>dirk dierickx</dc:creator>
      <dc:date>2007-07-18T01:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039057#M302573</link>
      <description>You can try the following&lt;BR /&gt;&lt;BR /&gt;/usr/sbin/visudo&lt;BR /&gt;&lt;BR /&gt;Under Cmnd alias specification&lt;BR /&gt;&lt;BR /&gt;Cmnd_Alias  ABCD=&amp;lt;script path&amp;gt;&lt;BR /&gt;&lt;BR /&gt;Under User privilege specification&lt;BR /&gt;&lt;BR /&gt;Username NOPASSWD: ABCD&lt;BR /&gt;&lt;BR /&gt;If the user is already present in sudoers file, add (NOPASSWD: ABCD) at the end of the line.&lt;BR /&gt;Now run the scipt as &lt;BR /&gt;&lt;BR /&gt;sudo &amp;lt;script path&amp;gt;&lt;BR /&gt;&lt;BR /&gt;Please remove write permission for the user on the script. He shud have only read and execute. If he is given write permission on the script, he can modify the script for his needs.&lt;BR /&gt;This shud work, without a password and with violating security issues.&lt;BR /&gt;&lt;BR /&gt;Ravi.</description>
      <pubDate>Wed, 18 Jul 2007 02:05:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039057#M302573</guid>
      <dc:creator>G V R Shankar</dc:creator>
      <dc:date>2007-07-18T02:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039058#M302574</link>
      <description>It cannot be stressed enough what Bill wrote.&lt;BR /&gt;I think this madness derives from settings in certain Live Linux or Ubuntu distros?</description>
      <pubDate>Wed, 18 Jul 2007 02:21:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039058#M302574</guid>
      <dc:creator>Ralph Grothe</dc:creator>
      <dc:date>2007-07-18T02:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is this possible with sudo !!!</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039059#M302575</link>
      <description>The optimum way to fulfill the original requirement would be something like this line in the sudoers file:&lt;BR /&gt;&lt;BR /&gt;user host = (root) NOPASSWD: /usr/bin/su - root -c &amp;lt;script&amp;gt;&lt;BR /&gt;&lt;BR /&gt;This will allow the user to run only this one script as root without asking for a password.&lt;BR /&gt;The user must then run the script _using exactly that specified command line_. The "&amp;lt;script&amp;gt;" should be specified as a full path, and the user must then always write it exactly the same way.&lt;BR /&gt;&lt;BR /&gt;If you're sure you won't *ever* copy this sudoers file to other hosts without carefully inspecting it first, you can replace the "host" part with "ALL".&lt;BR /&gt;&lt;BR /&gt;Note that you must always use a full path when identifying the commands the user may execute (i.e. "/usr/bin/su" instead of just "su"). If you don't use a full path, visudo will not accept it, because the user would be able to exploit the definition easily by changing his PATH setting.&lt;BR /&gt;&lt;BR /&gt;Because visudo cannot verify the command arguments, it cannot force you to use a full path in "&amp;lt;script&amp;gt;". To keep your system secure, you must use a full path in this too.&lt;BR /&gt;&lt;BR /&gt;As others have noted, the script (and the directory the script is located in) *must not* be writeable by the user. &lt;BR /&gt;&lt;BR /&gt;Furthermore, if the script uses command line parameters or other user-supplied data, the script must be written *very very carefully*: if the script contains even a single unquoted parameter or variable expansion (like $1 or $something), the user might be able to gain unrestricted root by using strategically-placed semicolons in the parameters or other input.&lt;BR /&gt;&lt;BR /&gt;MK</description>
      <pubDate>Wed, 18 Jul 2007 06:24:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/is-this-possible-with-sudo/m-p/4039059#M302575</guid>
      <dc:creator>Matti_Kurkela</dc:creator>
      <dc:date>2007-07-18T06:24:03Z</dc:date>
    </item>
  </channel>
</rss>

