Why we should set arguments in sudoers configuration?

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
1
down vote

favorite












Why should we set arguments in sudoers configuration? For example



user ALL= EXEC: PASSWD: /sbin/reboot -f ""


here I can call only "reboot -f" command. So if I set



user ALL= EXEC: PASSWD: /sbin/reboot -f *


or



user ALL= EXEC: PASSWD: /sbin/reboot


How can someone use this to hack or do something?



Best regards, Alex.







share|improve this question
















  • 1




    Consider reboot -p, then drive three hours to restart the machine.
    – Satō Katsura
    Oct 20 '17 at 8:02






  • 1




    Imagine needing to give rights to service or systemctl. You want to make very sure they can only restart their own service.
    – Ulrich Schwarz
    Oct 20 '17 at 8:08














up vote
1
down vote

favorite












Why should we set arguments in sudoers configuration? For example



user ALL= EXEC: PASSWD: /sbin/reboot -f ""


here I can call only "reboot -f" command. So if I set



user ALL= EXEC: PASSWD: /sbin/reboot -f *


or



user ALL= EXEC: PASSWD: /sbin/reboot


How can someone use this to hack or do something?



Best regards, Alex.







share|improve this question
















  • 1




    Consider reboot -p, then drive three hours to restart the machine.
    – Satō Katsura
    Oct 20 '17 at 8:02






  • 1




    Imagine needing to give rights to service or systemctl. You want to make very sure they can only restart their own service.
    – Ulrich Schwarz
    Oct 20 '17 at 8:08












up vote
1
down vote

favorite









up vote
1
down vote

favorite











Why should we set arguments in sudoers configuration? For example



user ALL= EXEC: PASSWD: /sbin/reboot -f ""


here I can call only "reboot -f" command. So if I set



user ALL= EXEC: PASSWD: /sbin/reboot -f *


or



user ALL= EXEC: PASSWD: /sbin/reboot


How can someone use this to hack or do something?



Best regards, Alex.







share|improve this question












Why should we set arguments in sudoers configuration? For example



user ALL= EXEC: PASSWD: /sbin/reboot -f ""


here I can call only "reboot -f" command. So if I set



user ALL= EXEC: PASSWD: /sbin/reboot -f *


or



user ALL= EXEC: PASSWD: /sbin/reboot


How can someone use this to hack or do something?



Best regards, Alex.









share|improve this question











share|improve this question




share|improve this question










asked Oct 20 '17 at 7:59









TheFdu4

233




233







  • 1




    Consider reboot -p, then drive three hours to restart the machine.
    – Satō Katsura
    Oct 20 '17 at 8:02






  • 1




    Imagine needing to give rights to service or systemctl. You want to make very sure they can only restart their own service.
    – Ulrich Schwarz
    Oct 20 '17 at 8:08












  • 1




    Consider reboot -p, then drive three hours to restart the machine.
    – Satō Katsura
    Oct 20 '17 at 8:02






  • 1




    Imagine needing to give rights to service or systemctl. You want to make very sure they can only restart their own service.
    – Ulrich Schwarz
    Oct 20 '17 at 8:08







1




1




Consider reboot -p, then drive three hours to restart the machine.
– Satō Katsura
Oct 20 '17 at 8:02




Consider reboot -p, then drive three hours to restart the machine.
– Satō Katsura
Oct 20 '17 at 8:02




1




1




Imagine needing to give rights to service or systemctl. You want to make very sure they can only restart their own service.
– Ulrich Schwarz
Oct 20 '17 at 8:08




Imagine needing to give rights to service or systemctl. You want to make very sure they can only restart their own service.
– Ulrich Schwarz
Oct 20 '17 at 8:08















active

oldest

votes











Your Answer







StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "106"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
convertImagesToLinks: false,
noModals: false,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













 

draft saved


draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f399287%2fwhy-we-should-set-arguments-in-sudoers-configuration%23new-answer', 'question_page');

);

Post as a guest



































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes















 

draft saved


draft discarded















































 


draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f399287%2fwhy-we-should-set-arguments-in-sudoers-configuration%23new-answer', 'question_page');

);

Post as a guest













































































Popular posts from this blog

How to check contact read email or not when send email to Individual?

Bahrain

Postfix configuration issue with fips on centos 7; mailgun relay