[ Date Index ]
[ Thread Index ]
[ <= Previous by date /
thread ]
[ Next by date /
thread => ]
Re: [LUG] Security Thoughts
- To: DCLUG ML <list@xxxxxxxxxxxxx>
- Subject: Re: [LUG] Security Thoughts
- From: Brad Rogers via list <list@xxxxxxxxxxxxx>
- Date: Thu, 30 Mar 2017 19:20:20 +0100
- Delivered-to: dclug@xxxxxxxxxxxxxxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=dclug.org.uk; s=1475831162; h=Sender:Content-Type:Reply-To:From:List-Subscribe:List-Help:List-Post:List-Unsubscribe:List-Id:Subject:MIME-Version:References:In-Reply-To:Message-ID:To:Date; bh=EVIlKRXjXs+mffkbf22wb/XmhbNYwODHN5YA1xb1J2E=; b=RN+U3p8zxuPCIlmjnyYQm/ZmjhXCY6qRz6mt3klni4kiY4gbaP4tiTD/HTrjJlv8yYvSDVCkn238j092AljOFINFSXjCnBMNnYEZ7ME9jJpoBvRtTi1XtaR/UsSEk/yZ4BvOjiNecEE3ONX+QSmpEDytVmP/W7j+8l1BIi86NB0=;
- Dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=fineby.me.uk; s=default; h=Content-Type:MIME-Version:Reply-To:References: In-Reply-To:Message-ID:Subject:To:From:Date:Sender:Cc: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=Tm80e0p20aYuS3rrg1Lmk/MCR5xucxeuh0Jo39EXJ38=; b=0Fn7j4wvmKgvRd6K5kYoWcDUj RNeqhOdxgNy73S39beGUjiI4yRustm6HUwenFq6lOuCqYnCrcJENzNHsWPCOqLHcncHQLSXQEJ30w BivK3nlNx/x+PcCF9SarQx/PBLflV0qrotiC3RhZYWsrKQg7zRFH3IcGmqgj91yUK8ZFPkgKJeWRM rOeGKQ8hrrJjBZ6uzDBJBhBRJMcRm3eRbWiwaPcMz9NfUq4ZVeYNbq9W4voYTywg8VyQVfGXAxKbN KSBfjNr6imv5xPBcHQVY8y5pkAxctc6RBOG6GrvDe5OaPf1APKZUC0xJC4kx4u71hV9kSZvIyWJCF x3jXXfUFQ==;
- Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAJFBMVEX/B9ftEdn/B9r/CdtREj//Btf/CNr/B9m3H7b+Dd7/Btj/Btvfr93OAAACbElEQVQ4jWWTwWsTQRTGX5Wtpl4cbGHWXAQRkV4CEaF4aWAOU3LZUgfaeOzJsxQJXlzc4MRcsiRipnsxSChNLgm1kO38c76ZndkkOodh+X7zvW/ezCyo/0ZKSKhSUG0vDACibVED1QczVOXAgT5EwQMBUOkHEFVgcAHFelUDYQYuxvkEBuKqYkn9RYBCFAnLI+iLk6LWox1rQKmY0VG35HlQgL7wjnt16zj/NBGrcYaO+0V4/eXVGsBdiXPXRv2NcNVEFKADXB/5/ttbUWzJllKBb3D0ZBMIB9JkgODsoAyHV8V6PjTAhxjHtQW7bPh13CnJNQJzvGk3ZQl7yL2+bRy5Wd9VjDPeOW0U4OMH+Cm0Ukl6pHZ5cnjKpevvF1y2cjViXYlTPH9Xgjl2jqXY0XAoGwuG49CC9hwzbjCCj5LmgiUNxmx+q/0MVA0zhox2U8kSTiIutswFClAXM9wt4yltYqFEdrYkHuWOwAx0KBomPbmLG47HUu4JMROQWaAka75esqRzjDqxN4hAGz3hyy8sXlD5jZDAgpbWOm+Mhkw3+VhSQshe6dDYAWeyt5Dy+3G8VzyGSzFDYjbENZW4/rF7JZl4j4BKNs9pr6fJU1EC4/jT43op4wUh/qbghwVLVqV0TffhWlep7FZJrlv+1XlApQnGj6kHlxaQ2Om6tXKYjFiGJM2s986DyUyrjIaEVK2ub9cysgz/yLDQtUs3V5uZPzVUuZFnUxcCSpvnk4ZKFRG6DJ/s5+5V2+hJ6Zj9Ln99A6YuBAY6L0G2kXF3sw58G6aU9nqeb4DPJcgG62f1TwY6Ws6x0j2aALK/gtD+T+UWL5UAAAAASUVORK5CYII=
On Thu, 30 Mar 2017 18:26:42 +0100
"M. J. Everitt via list" <list@xxxxxxxxxxxxx> wrote:
Hello M.,
>(for gnome-based apps). You don't use 'sudo' if there's a root password
>set, you can just use 'su' (instead of prompting for the user password,
>you enter the root password). You may wish to check/change your
I know it's academic on a single user system, but there are sound
reasons for offering only sudo rather than allowing su:
First, passing around the root password isn't required.
Second, sudo actions are logged so sysadmin knows who tried to do what
and when (you mentioned this, I know).
Makes it a hell of a lot easier to point the finger of blame. :-)
--
Regards _
/ ) "The blindingly obvious is
/ _)rad never immediately apparent"
You destroyed my confidence, you broke my nerve
Nervous Wreck - Radio Stars
Attachment:
pgpBGx7PscyWk.pgp
Description: OpenPGP digital signature
--
The Mailing List for the Devon & Cornwall LUG
https://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq