OpenSSH 8.0 released
OpenSSH 8.0 released
Posted Apr 30, 2019 15:07 UTC (Tue) by nix (subscriber, #2304)In reply to: OpenSSH 8.0 released by mbunkus
Parent article: OpenSSH 8.0 released
As soon as you grant a user sudo without a password to any program that can write to arbitrary files (rsync, tar, cp, sed, awk, tee, bash, Perl, Python, whatever), that account becomes root for all intents and purposes.Not for all: the user is still protected from typos and accidents -- just not from malicious attackers executing code as the user.
