Ian Molton spyro at f2s.com
Mon Jan 12 01:26:11 PST 2004

On Mon, 12 Jan 2004 17:47:37 +1100
Ryan.Oliver at pha.com.au wrote:

> > AFAIK, wouldn't it be an almost trivial fix to just change file
> > permissions on su (and any other potentially root giving program) to
> >  750 so that only people in its group can run it, and then add it to
> >  the group wheel, or admin or something similar.  That way only
> >  users with the appropriate group could even use the su command.
> Don't use coreutils su, use shadow's su and you'll get the behaviour
> you are expecting...

TBH I'd prefer to rely on the kernels permission checking than a user
space program - the kernel routines get a lot more of a workout...

