LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 08-15-2016, 04:15 PM   #1
jwgathumbi
LQ Newbie
 
Registered: Mar 2012
Posts: 3

Rep: Reputation: Disabled
Unhappy Error "command not allowed" LinixServer


Hi Folks need some help figuring out a log event per the log events below. Both events seem similar yet event #1 was not allowed. Yet afew minutes later, the same command was allowed as shown by event #2. What am i missing here?
1. Privilege Escalation Failed u07c04 LinuxServer @ plup5066 1 Aug 5, 2016, 1:25:08 PM Privilege Escalation Failed 10.10.10.185 10.10.10.150 5 <33>Aug 5 13:25:08 plup5066 sudo: u07c04 : command not allowed ; TTY=pts/0 ; PWD=/home/u07c04 ; USER=root ; COMMAND=/bin/su -

2. Privilege Escalation Succeeded u07c04 LinuxServer @ plup5066 1 Aug 5, 2016, 1:28:32 PM Privilege Escalation Succeeded 10.10.10.185 10.10.10.150 4 <37>Aug 5 13:28:32 plup5066 sudo: u07c04 : TTY=pts/0 ; PWD=/home/u07c04 ; USER=root ; COMMAND=/bin/su -
 
Old 08-15-2016, 05:39 PM   #2
Upuetz
Member
 
Registered: May 2016
Location: Aachen
Distribution: Debian, CentOS, Ubuntu, Raspian, tinycore
Posts: 59

Rep: Reputation: Disabled
Hi,
I deduce from your question that you didn't run that command? If so, then I think user u07c04 managed to run the command (sudo) su -, which means he has now root access.

To be frank, I'm not entirely certain that's what happenend but it might be from your excerpts above.
HTH
Upuetz
 
Old 08-15-2016, 07:23 PM   #3
jwgathumbi
LQ Newbie
 
Registered: Mar 2012
Posts: 3

Original Poster
Rep: Reputation: Disabled
Angry

Hello-
What i do not understand is why the first event (#1) was deemed "command not allowed" yet a few minutes later, the same user run the same command on the same server and it was successful. That's my dilemma.
 
Old 08-16-2016, 03:41 AM   #4
Upuetz
Member
 
Registered: May 2016
Location: Aachen
Distribution: Debian, CentOS, Ubuntu, Raspian, tinycore
Posts: 59

Rep: Reputation: Disabled
Maybe that user was able to change the sudoers file? Or the rights of /bin/su?
Both would be bad...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Is it allowed to use full path to "*.desktop" files in the "mimeapps.list"? Andy_Crowd Linux - Newbie 1 05-12-2016 03:17 PM
gigabyte U7300 "edit Makefile" command returns "error" drobin Linux - Newbie 8 09-04-2013 04:20 AM
Samba error: "not an allowed info level" catkin Linux - Server 1 12-05-2009 12:52 PM
ns:"error when calling class OldSim"&tclsh:"invalid command+child process exits abn." shojaru Linux - Newbie 0 03-05-2009 04:23 AM
LFS6.3 livecd "ls : command not found" error after "su - lfs" rotu Linux From Scratch 2 06-19-2008 03:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 08:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration