ä¸. ä½¿ç¨ su å½ä»¤ä¸´æ¶åæ¢ç¨æ·èº«ä»½
1ãsu çéç¨æ¡ä»¶åå¨å
suå½ä»¤å°±æ¯åæ¢ç¨æ·çå·¥å
·ï¼æä¹ç解å¢ï¼æ¯å¦æ们以æ®éç¨æ·beinanç»å½çï¼ä½è¦æ·»å ç¨æ·ä»»å¡ï¼æ§è¡useradd ï¼beinanç¨æ·æ²¡æè¿ä¸ªæéï¼èè¿ä¸ªæéæ°æ°ç±rootææ¥æã解å³åæ³æ æ³æ两个ï¼ä¸æ¯éåºbeinanç¨æ·ï¼éæ°ä»¥rootç¨æ·ç»å½ï¼ä½è¿ç§åæ³å¹¶ä¸æ¯æ好çï¼äºæ¯æ们没æå¿
è¦éåºbeinanç¨æ·ï¼å¯ä»¥ç¨suæ¥åæ¢å°rootä¸è¿è¡æ·»å ç¨æ·çå·¥ä½ï¼çä»»å¡å®æååéåºrootãæ们å¯ä»¥çå°å½ç¶éè¿su åæ¢æ¯ä¸ç§æ¯è¾å¥½çåæ³ï¼
éè¿suå¯ä»¥å¨ç¨æ·ä¹é´åæ¢ï¼å¦æè¶
级æéç¨æ·rootåæ®éæèæç¨æ·åæ¢ä¸éè¦å¯ç ï¼ä»ä¹æ¯æåï¼è¿å°±æ¯ï¼èæ®éç¨æ·åæ¢å°å
¶å®ä»»ä½ç¨æ·é½éè¦å¯ç éªè¯ï¼
2ãsu çç¨æ³ï¼
su [OPTIONé项åæ°] [ç¨æ·]
-, -l, ââlogin ç»å½å¹¶æ¹åå°æåæ¢çç¨æ·ç¯å¢ï¼
-c, ââcommmand=COMMAND æ§è¡ä¸ä¸ªå½ä»¤ï¼ç¶åéåºæåæ¢å°çç¨æ·ç¯å¢ï¼
è³äºæ´è¯¦ç»çï¼è¯·åçman su ï¼
3ãsu çèä¾ï¼
1) su å¨ä¸å ä»»ä½åæ°
é»è®¤ä¸ºåæ¢å°rootç¨æ·ï¼ä½æ²¡æ转å°rootç¨æ·å®¶ç®å½ä¸ï¼ä¹å°±æ¯è¯´è¿æ¶è½ç¶æ¯åæ¢ä¸ºrootç¨æ·äºï¼ä½å¹¶æ²¡ææ¹årootç»å½ç¯å¢ï¼ç¨æ·é»è®¤çç»å½ç¯å¢ï¼å¯ä»¥å¨/etc/passwd ä¸æ¥å¾å°ï¼å
æ¬å®¶ç®å½ï¼SHELLå®ä¹çï¼
[beinan@localhost ~]?$ su root
Password:
[root@localhost beinan]# pwd
/home/beinan
2) su å åæ° -
表示é»è®¤åæ¢å°rootç¨æ·ï¼å¹¶ä¸æ¹åå°rootç¨æ·çç¯å¢ï¼
[beinan@localhost ~]$ pwd
/home/beinan
[beinan@localhost ~]$ su -
Password:
[root@localhost ~]# pwd
/root
3) su åæ° - ç¨æ·å
[beinan@localhost ~]$ su â root 注ï¼è¿ä¸ªåsu - æ¯ä¸æ ·çåè½ï¼
Password:
[root@localhost ~]# pwd
/root
[beinan@localhost ~]$ su â linuxsir 注ï¼è¿æ¯åæ¢å° linuxsirç¨æ·
Password: 注ï¼å¨è¿éè¾å
¥å¯ç ï¼
[linuxsir@localhost ~]$ pwd 注ï¼æ¥çç¨æ·å½åæå¤çä½ç½®ï¼
/home/linuxsir
[linuxsir@localhost ~]$ id 注ï¼æ¥çç¨æ·çUIDåGIDä¿¡æ¯ï¼ä¸»è¦æ¯çæ¯å¦åæ¢è¿æ¥äºï¼
uid=505(linuxsir) gid=502(linuxsir) groups=0(root),500(beinan),502(linuxsir)
[linuxsir@localhost ~]$ exit 注ï¼éåº
logout
[beinan@localhost ~]$
[beinan@localhost Desktop]$ su - -c ls 注ï¼è¿æ¯suçåæ°ç»åï¼è¡¨ç¤ºåæ¢å°rootç¨æ·ï¼å¹¶ä¸æ¹åå°rootç¯å¢ï¼ç¶åååºroot家ç®å½çæ件ï¼ç¶åéåºrootç¨æ·ï¼
Password: 注ï¼å¨è¿éè¾å
¥rootçå¯ç ï¼
anaconda-ks.cfg install.log.syslog mydate1 mytask.sh Videos æ³¨ï¼ ååºroot家ç®å½çæ件ï¼
Desktop jdk mydate2 Pictures workspace
Documents jdk-6u13-linux-i586.bin mydate3 Public Workspaces
Downloads Linux mydate4 software
install.log Music MyEclipse 2015 Templates
[beinan@localhost Desktop]$ 注ï¼èªå¨éåºrootç¨æ·ï¼
[beinan@localhost Desktop]$ pwd
/home/beinan/Desktop
[beinan@localhost Desktop]$ id 注ï¼æ¥çæ¯å¦åæ¢æåï¼
uid=506(beinan) gid=506(beinan) groups=506(beinan) context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023
[beinan@localhost Desktop]$
4ãsuçä¼ç¼ºç¹ï¼
su ç确为管ç带æ¥æ¹ä¾¿ï¼éè¿åæ¢å°rootä¸ï¼è½å®æææç³»ç»ç®¡çå·¥å
·ï¼åªè¦ærootçå¯ç 交ç»ä»»ä½ä¸ä¸ªæ®éç¨æ·ï¼ä»é½è½åæ¢å°rootæ¥å®æææçç³»ç»ç®¡çå·¥ä½ï¼ä½éè¿suåæ¢å°rootåï¼ä¹æä¸å®å
¨å ç´ ï¼æ¯å¦ç³»ç»æ10个ç¨æ·ï¼èä¸é½åä¸ç®¡çãå¦æè¿10个ç¨æ·é½æ¶åå°è¶
级æéçè¿ç¨ï¼å为管çåå¦ææ³è®©å
¶å®ç¨æ·éè¿suæ¥åæ¢å°è¶
级æéçrootï¼å¿
é¡»ærootæéå¯ç é½åè¯è¿10个ç¨æ·ï¼å¦æè¿10个ç¨æ·é½ærootæéï¼éè¿rootæéå¯ä»¥åä»»ä½äºï¼è¿å¨ä¸å®ç¨åº¦ä¸å°±å¯¹ç³»ç»çå®å
¨é æäºå¨åï¼æ³æ³Windowså§ï¼ç®ç´å°±æ¯æ¶æ¢¦ï¼â没æä¸å®å
¨çç³»ç»ï¼åªæä¸å®å
¨ç人âï¼æ们ç»å¯¹ä¸è½ä¿è¯è¿ 10个ç¨æ·é½è½ææ£å¸¸æä½æµç¨æ¥ç®¡çç³»ç»ï¼å
¶ä¸ä»»ä½ä¸äººå¯¹ç³»ç»æä½çé大失误ï¼é½å¯è½å¯¼è´ç³»ç»å´©æºææ°æ®æ失ï¼æ以su å·¥å
·å¨å¤äººåä¸çç³»ç»ç®¡çä¸ï¼å¹¶ä¸æ¯æ好çéæ©ï¼suåªéç¨äºä¸ä¸¤ä¸ªäººåä¸ç®¡ççç³»ç»ï¼æ¯ç«su并ä¸è½è®©æ®éç¨æ·åéç使ç¨ï¼è¶
级ç¨æ·rootå¯ç åºè¯¥ææ¡å¨å°æ°ç¨æ·æä¸ï¼è¿ç»å¯¹æ¯ççï¼æ以éæèæ²»çåå¨è¿æ¯æä¸å®éççï¼
äº. sudo ææ许å¯ä½¿ç¨çsuï¼ä¹æ¯åéå¶çsu
1. sudo çéç¨æ¡ä»¶
ç±äºsu 对åæ¢å°è¶
级æéç¨æ·rootåï¼æéçæ éå¶æ§ï¼æ以su并ä¸è½æ
ä»»å¤ä¸ªç®¡çåæ管ççç³»ç»ãå¦æç¨su æ¥åæ¢å°è¶
级ç¨æ·æ¥ç®¡çç³»ç»ï¼ä¹ä¸è½æç¡®åªäºå·¥ä½æ¯ç±åªä¸ªç®¡çåè¿è¡çæä½ãç¹å«æ¯å¯¹äºæå¡å¨ç管çæå¤äººåä¸ç®¡çæ¶ï¼æ好æ¯é对æ¯ä¸ªç®¡çåçææ¯ç¹é¿å管çèå´ï¼å¹¶ä¸æé对æ§çä¸æ¾ç»æéï¼å¹¶ä¸çº¦å®å
¶ä½¿ç¨åªäºå·¥å
·æ¥å®æä¸å
¶ç¸å
³çå·¥ä½ï¼è¿æ¶æ们就æå¿
è¦ç¨å° sudoã
éè¿sudoï¼æ们è½ææäºè¶
级æéæé对æ§çä¸æ¾ï¼å¹¶ä¸ä¸éè¦æ®éç¨æ·ç¥érootå¯ç ï¼æ以sudo ç¸å¯¹äºæéæ éå¶æ§çsuæ¥è¯´ï¼è¿æ¯æ¯è¾å®å
¨çï¼æ以sudo ä¹è½è¢«ç§°ä¸ºåéå¶çsu ï¼å¦å¤sudo æ¯éè¦ææ许å¯çï¼æ以ä¹è¢«ç§°ä¸ºææ许å¯çsuï¼
2. sudo æ§è¡å½ä»¤çæµç¨
1ï¼ç»ç¨æ·ææ
å½åç¨æ·åæ¢å°rootï¼æå
¶å®æå®åæ¢å°çç¨æ·ï¼ï¼ç¶å以rootï¼æå
¶å®æå®çåæ¢å°çç¨æ·ï¼èº«ä»½æ§è¡å½ä»¤ï¼æ§è¡å®æåï¼ç´æ¥éåå°å½åç¨æ·ï¼èè¿äºçåææ¯è¦éè¿sudoçé
ç½®æ件/etc/sudoersæ¥è¿è¡ææï¼
æ¯å¦æ们æ³ç¨beinanæ®éç¨æ·éè¿more /etc/shadowæ件çå
容æ¶ï¼å¯è½ä¼åºç°ä¸é¢çæ
åµï¼
[beinan@localhost ~]$ more /etc/shadow/etc/shadow
/etc/shadow: Permission denied 注ï¼æéä¸å¤
[beinan@localhost ~]$
è¿æ¶æ们å¯ä»¥ç¨sudo more /etc/shadow æ¥è¯»åæ件çå
容ï¼å°±å°±éè¦å¨/etc/soduersä¸ç»beinanææï¼äºæ¯æ们就å¯ä»¥å
su å°rootç¨æ·ä¸éè¿visudo æ¥æ¹/etc/sudoers ï¼ï¼æ¯å¦æ们æ¯ä»¥beinanç¨æ·ç»å½ç³»ç»çï¼
[beinan@localhost ~]$ su
Password: 注ï¼å¨è¿éè¾å
¥rootå¯ç
[root@localhost beinan]# visudo 注ï¼è¿è¡visudo æ¥æ¹ /etc/sudoers
å å
¥å¦ä¸ä¸è¡ beinan ALL=/bin/moreï¼éåºä¿åï¼
注ï¼visudoä¹æ¯ç¨çviç¼è¾å¨ï¼beinan ALL=/bin/more 表示beinanå¯ä»¥åæ¢å°rootä¸æ§è¡more æ¥æ¥çæ件ï¼éåå°beinanç¨æ·ä¸ï¼ç¨exitå½ä»¤ï¼
[root@localhost beinan]# exit
exit
[beinan@localhost ~]$
2ï¼beinanç¨æ·æ§è¡rootä¸çæéï¼æ¥çbeinançéè¿sudoè½æ§è¡åªäºå½ä»¤
[beinan@localhost ~]?$ sudo -l
Password: 注ï¼å¨è¿éè¾å
¥beinanç¨æ·çå¯ç
User beinan may run the following commands on this host:
(root) /bin/more 注ï¼å¨è¿éæ¸
æ°ç说æå¨æ¬å°ä¸»æºä¸ï¼beinanç¨æ·å¯ä»¥ä»¥rootæéè¿è¡more ï¼å¨rootæéä¸çmore ï¼å¯ä»¥æ¥çä»»ä½ææ¬æ件çå
容çï¼
æåï¼æ们ççæ¯ä¸æ¯beinanç¨æ·æè½åçå°/etc/shadowæ件çå
容ï¼
[beinan@localhost ~]$ sudo more /etc/shadow
root:$1$mKOQVMQ8$kg3pR0NI4XBgX8KTk4OJI/:16541:0:99999:7:::
bin:*:15980:0:99999:7:::
daemon:*:15980:0:99999:7:::
adm:*:15980:0:99999:7:::
lp:*:15980:0:99999:7:::
sync:*:15980:0:99999:7:::
shutdown:*:15980:0:99999:7:::
halt:*:15980:0:99999:7:::
mail:*:15980:0:99999:7:::
beinan ä¸ä½è½çå° /etc/shadowæ件çå
容ï¼è¿è½çå°åªærootæéä¸æè½çå°çå
¶å®æ件çå
容ï¼æ¯å¦ï¼
[beinan@localhost ~]$ sudo more /etc/gshadow
[sudo] password for beinan:
root:::
bin:::bin,daemon
daemon:::bin,daemon
sys:::bin,adm
adm:::adm,daemon
tty:::
disk:::
lp:::daemon
mem:::
kmem:::
wheel:::
mail:::mail,postfix
uucp:::
对äºbeinanç¨æ·æ¥çå读åææç³»ç»æ件ä¸ï¼æåªæ³æ/etc/shadow çå
容å¯ä»¥è®©ä»æ¥çï¼å¯ä»¥å å
¥ä¸é¢çä¸è¡ï¼
beinan ALL=/bin/more /etc/shadow
é¢å¤è¯ï¼æçå¼å
ä¼è¯´ï¼æéè¿su åæ¢å°rootç¨æ·å°±è½çå°æææ³ççå
容äºï¼ååï¼å¯¹åãä½å±ä»¬ç°å¨ä¸æ¯å¨è®²è¿°sudoçç¨æ³åï¼å¦æ主æºä¸æå¤ä¸ªç¨æ·å¹¶ä¸ä¸ç¥érootç¨æ·çå¯ç ï¼ä½åæ³æ¥çæäºä»ä»¬çä¸å°çæ件ï¼è¿æ¶å°±éè¦ç®¡çåææäºï¼è¿å°±æ¯sudoç好å¤ï¼
3ï¼ç¨æ·ç»å¨/etc/sudoersä¸åæ³
å¦æç¨æ·ç»åºç°å¨/etc/sudoers ä¸ï¼åé¢è¦å %å·ï¼æ¯å¦%beinan ï¼ä¸é´ä¸è½æç©ºæ ¼ï¼%beinan ALL=/usr/sbin/*,/sbin/*
å¦ææä»¬å¨ /etc/sudoers ä¸å ä¸å¦ä¸ä¸è¡ï¼è¡¨ç¤ºbeinanç¨æ·ç»ä¸çæææåï¼å¨ææå¯è½çåºç°ç主æºåä¸ï¼é½è½åæ¢å°rootç¨æ·ä¸è¿è¡ /usr/sbinå/sbinç®å½ä¸çææå½ä»¤ï¼
4ï¼åæ¶æç±»ç¨åºçæ§è¡
åæ¶ç¨åºæç±»ç¨åºçæ§è¡ï¼è¦å¨å½ä»¤å¨ä½åé¢å ä¸!å·ï¼ å¨æ¬ä¾ä¸ä¹åºç°äºéé
符ç*çç¨æ³ï¼
beinan ALL=/usr/sbin/*,/sbin/*,!/usr/sbin/fdisk 注ï¼æè¿è¡è§åå å
¥å°/etc/sudoersä¸ï¼ä½æ¨å¾æbeinanè¿ä¸ªç¨æ·ç»ï¼å¹¶ä¸beinanä¹æ¯è¿ä¸ªç»ä¸çæè¡ï¼
æ¬è§å表示beinanç¨æ·å¨ææå¯è½åå¨ç主æºåç主æºä¸è¿è¡/usr/sbinå/sbinä¸ææçç¨åºï¼ä½fdisk ç¨åºé¤å¤ï¼
[beinan@localhost ~]$ sudo -l
Password: 注ï¼å¨è¿éè¾å
¥beinanç¨æ·çå¯ç ï¼
User beinan may run the following commands on this host:
(root) /usr/sbin/*(root) /sbin/*(root) !/sbin/fdisk
[beinan@localhost ~]$ sudo /sbin/fdisk âl
Sorry, user beinan is not allowed to execute '/sbin/fdisk -l' as root on localhost.
注ï¼ä¸è½åæ¢å°rootç¨æ·ä¸è¿è¡fdisk ç¨åºï¼
å¦ææsudo çæéè没æsuçæé: sudo su;
温馨提示:答案为网友推荐,仅供参考