does your shop use jamf to manage? possibly something was misconfigured?
s
Shawn Maddock
04/05/2025, 1:36 PM
Hmm. We don’t use Jamf, and haven’t enabled the equivalent of an EA that would be doing this. Current assumption is one of our RMM tools is doing something from the vendor side. With it reading and writing from the root account but still using sudo, feels like a Windows dev trying to do cross-platform stuff poorly.
Shawn Maddock
04/05/2025, 1:37 PM
The “echo value:” def feels like an EA
f
FG
04/05/2025, 2:44 PM
the order of the commands looks to be exactly the script/gist I posted, can you search the endpoint to see if there is such a shell script or something in cron? definitely seems odd.
s
Shawn Maddock
04/05/2025, 2:57 PM
I did, couldn’t find any shell scripts or launchdaemons that had those actual commands. And it’s not just one endpoint. That gist is written better though… there’s no reason for root to be calling sudo for those commands, and the repeated reads and lists feels like some tool trying to enforce the settings