What's the best way to mitigate NFS and sudo?

Posted by user225874 on Server Fault See other posts from Server Fault or by user225874
Published on 2014-06-12T03:35:15Z Indexed on 2014/06/12 15:28 UTC
Read the original article Hit count: 317

Filed under:
|
|
|

Quick background: We have 40 workstations running Linux. NFS is used extensively for bulk data storage and home directories. This allows users to roam freely will relatively transparent file systems.

This is an educational environment where postdocs and students have successfully pulled off a coup of sorts. All have gained root on their individual workstations by grooming a technophobic PI who thinks IT people are evil. If I so much as suggest chroot or sudo restrictions, I'll find myself working out of a broom closet.

With that in mind, what's the best way to mitigate something like this below?

$ hostname
workstation1
$ whoami
john
$ sudo su jane
$ whoami
jane
$ cp -R /home/nfs/jane /mnt/thumbdrive/ 

© Server Fault or respective owner

Related posts about linux

Related posts about nfs