Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Problems 'su'ing into the root user



On Aug 22, 2006, at 9:35 AM, Dave Schroeder wrote:
No, that is the general advantages of using "sudo" over "su".

That is not the difference between "sudo -s" and "sudo su", which are functionally equivalent. Neither "sudo -s" nor "sudo su" require the root account to be enabled/assigned a password, both let you type the wrong things, neither log beyond the initial event, and both are allowed by the default sudoers configuratin on OS X.

(See my previous message for more.)

Please note that these *are* good reasons to use sudo versus ANY kind of root shell, not just one provided by "su". There are other ways to get root shells, such as "sudo -s". However, the original question is about the differences between "sudo -s" and "sudo su", because some people always say "if you need a root shell, use 'sudo -s'; you should never use 'sudo su'", and that doesn't make any sense. Both do the same thing (essentially, with the exception of the difference I noted in my previous message), neither log, and neither require the root account to be enabled.

sure....

'sudo su' spawns three processes.

sudo, su, then the shell.

'sudo -s' spawns two.

from a security standpoint, that's fewer points of failure.



_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macos-x-server mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/macos-x-server/email@hidden

This email sent to email@hidden
References: 
 >Problems 'su'ing into the root user (From: Nate Rudd <email@hidden>)
 >Re: Problems 'su'ing into the root user (From: Simon Slavin <email@hidden>)
 >Re: Problems 'su'ing into the root user (From: Ansgar -59cobalt- Wiechers <email@hidden>)
 >Re: Problems 'su'ing into the root user (From: JC Derr <email@hidden>)
 >Re: Problems 'su'ing into the root user (From: Ansgar -59cobalt- Wiechers <email@hidden>)
 >Re: Problems 'su'ing into the root user (From: Simon Slavin <email@hidden>)
 >Re: Problems 'su'ing into the root user (From: Dave Schroeder <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.