Re: Fedora22 Security Issue.

2015-08-18 Thread Martin Cigorraga
Hi, I recently came up with this 'issue' (not really an issue in fact, please read along) when I configured a Webmin panel on a CentOS 6.7 instance we use at work. Thing is that the sudo tool provides a configuration flag to deny a command execution if it's not being invoked from a console. Origi

Re: Fedora22 Security Issue.

2015-08-18 Thread inode0
On Tue, Aug 18, 2015 at 2:09 AM, Scott Mattan wrote: > Hello, > > I am seeing some disparity between (two distributions granted) CentOS 6.6 > and Fedora22 in their use of the su utility. I cannot figure out the cause, > so I cannot fix it. > > In CentOS there is no way to script login to root...

Re: Fedora22 Security Issue.

2015-08-18 Thread Scott Mattan
I just tried the non-login-shell with those settings, and it didn't offer any change from the previous response. (I primarily work with CentOS6.6 at work but am testing Fedora at home and would like to implement similar security settings) [ user@localhost ~]$ su - < password > echo "" > id > EOF

Re: Fedora22 Security Issue.

2015-08-18 Thread Patrick O'Callaghan
On Wed, 2015-08-19 at 04:05 +0800, Ed Greshko wrote: > On 08/19/15 00:10, Patrick O'Callaghan wrote: > > On Wed, 2015-08-19 at 00:13 +0900, Scott Mattan wrote: > > > I havent tried comparing yet but ive verified that disabling > > > various > > > combinations on the cent machine does not produce th

Re: Fedora22 Security Issue.

2015-08-18 Thread Ed Greshko
On 08/19/15 00:10, Patrick O'Callaghan wrote: > On Wed, 2015-08-19 at 00:13 +0900, Scott Mattan wrote: >> I havent tried comparing yet but ive verified that disabling various >> combinations on the cent machine does not produce the same results. > Same results as what? Is this part of some other th

Re: Fedora22 Security Issue.

2015-08-18 Thread Patrick O'Callaghan
On Wed, 2015-08-19 at 00:13 +0900, Scott Mattan wrote: > I havent tried comparing yet but ive verified that disabling various > combinations on the cent machine does not produce the same results. Same results as what? Is this part of some other thread? poc -- users mailing list users@lists.fedo

Re: Fedora22 Security Issue.

2015-08-18 Thread Ed Greshko
On 08/18/15 15:09, Scott Mattan wrote: > > I am seeing some disparity between (two distributions granted) CentOS 6.6 and > Fedora22 in their use of the su utility. I cannot figure out the cause, so I > cannot fix it. > > In CentOS there is no way to script login to root... this is of course a >