Sudo Calls List

The following table lists available sudo commands along with their purpose and whether they can accept wildcards.

CommandWildcardsPurpose
/bin/chown -R <user> /opt/apps/verodin/node/nodeFALSEUpgrade Handling
/bin/netstat -anp | grep {process name}TRUENetwork Control
/bin/systemctl daemon-reloadFALSEService Control
/bin/systemctl disable chronydFALSENTP Control
/bin/systemctl enable chronydFALSENTP Control
/bin/systemctl mask nginxFALSEService Control
/bin/systemctl mask sshdFALSEService Control
/bin/systemctl mask verodin-backendFALSEService Control
/bin/systemctl mask verodin-network-monitorFALSEService Control
/bin/systemctl mask verodin-pullFALSEService Control
/bin/systemctl mask verodin-webFALSEService Control
/bin/systemctl reload nginxFALSEService Control
/bin/systemctl restart chronydFALSENTP Control
/bin/systemctl restart nginxFALSEService Control
/bin/systemctl restart verodin-backendFALSEService Control
/bin/systemctl restart verodin-network-monitorFALSEService Control
/bin/systemctl restart verodin-pullFALSEService Control
/bin/systemctl restart verodin-webFALSEService Control
/bin/systemctl start ssh-second.serviceFALSESSH Tunnel Control
/bin/systemctl start sshdFALSEService Control
/bin/systemctl stop chronydFALSENTP Control
/bin/systemctl stop nginxFALSEService Control
/bin/systemctl stop ssh-second.serviceFALSESSH Tunnel Control
/bin/systemctl stop sshdFALSEService Control
/bin/systemctl stop verodin-backendFALSEService Control
/bin/systemctl stop verodin-network-monitorFALSEService Control
/bin/systemctl stop verodin-pullFALSEService Control
/bin/systemctl stop verodin-webFALSEService Control
/bin/systemctl unmask nginxFALSEService Control
/bin/systemctl unmask sshdFALSEService Control
/bin/systemctl unmask verodin-backendFALSEService Control
/bin/systemctl unmask verodin-network-monitorFALSEService Control
/bin/systemctl unmask verodin-pullFALSEService Control
/bin/systemctl unmask verodin-webFALSEService Control
/opt/apps/verodin/node/ext/hans-master/hansTRUEICMP Tunnel
/opt/apps/verodin/node/ext/iodine/bin/iodineTRUEDNS Tunnel
/sbin/iptables -A INPUT -i lo -p tcp --dport <port> -j ACCEPTFALSEopen loopback port
/sbin/iptables -A INPUT -p {proto} -m multiport --dports {portstr} -m state --state NEW,ESTABLISHED -j ACCEPTTRUEFirewall Control
/sbin/iptables -A INPUT -p {protostr} --dport {portstr} -m state --state NEW,ESTABLISHED -j ACCEPTTRUEFirewall Control
/sbin/iptables -A INPUT -s {ipstr}/32 -p {protostr} --dport {portstr} -m state --state NEW,ESTABLISHED -j ACCEPTTRUEFirewall Control
/sbin/iptables -D INPUT -i lo -p tcp --dport <port> -j ACCEPTFALSEclose loopback port
/sbin/iptables -D INPUT -p {proto} -m multiport --dports {portstr} -m state --state NEW,ESTABLISHED -j ACCEPTTRUEFirewall Control
/sbin/iptables -D INPUT -p {protostr} --dport {portstr} -m state --state NEW,ESTABLISHED -j ACCEPTTRUEFirewall Control
/sbin/iptables -D INPUT -s {ipstr}/32 -p {protostr} --dport {portstr} -m state --state NEW,ESTABLISHED -j ACCEPTTRUEFirewall Control
/sbin/iptables-restore < /opt/apps/verodin/node/node/tmp/iptables/update.txtFALSEFirewall Control
/sbin/setcap CAP_NET_BIND_SERVICE=+eip /opt/apps/verodin/node/node/scripts/verodin_backend_serviceFALSEUpgrade Handling
/usr/bin/date -s {sign} {adjust} secondsTRUENTP Control
/usr/bin/sysctl -w net.ipv4.ip_local_reserved_ports=""FALSENetwork Control
/usr/bin/sysctl -w net.ipv4.ip_local_reserved_ports="{ports}"TRUENetwork Control
/usr/bin/sysctl -w net.ipv4.tcp_orphan_retries=0FALSEAction tcp orphan retry disable
/usr/bin/sysctl -w net.ipv4.tcp_orphan_retries=1FALSEAction tcp orphan retry enable
/usr/sbin/ifdown <nic>TRUEInterface Control
/usr/sbin/ifup <nic>TRUEInterface Control
/usr/sbin/ip link set {nic} downTRUEInterface Control
/usr/sbin/ip link set {nic} upTRUEInterface Control
/usr/sbin/ntpdate <ntphost>TRUENTP Control
/usr/sbin/shutdown -r nowFALSEShutdown
nmcli con reload {interface}TRUEInterface Route Handling
nmcli connection modify {interface} -ipv4.routes "{destination}/{cidr} {gateway}"TRUEInterface Route Handling
nmcli connection modify {interface} +ipv4.routes "{destination}/{cidr} {gateway}"TRUEInterface Route Handling
nmcli connection modify {interface} ipv4.route-metric {metric}TRUEInterface Route Handling
nmcli connection up {interface}TRUEInterface Route Handling
timedatectl set-ntp 0FALSENTP Control
timedatectl set-ntp 1FALSENTP Control
touch /opt/apps/verodin/node/node/settings.jsonFALSEActor Settings handling
  • June 5, 2022
  • September 25, 2023
In This Article