Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-amd64
Navigation:
Lists: gentoo-amd64: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-amd64@g.o
From: Duncan <1i5t5.duncan@...>
Subject: OT but something to think about (security and root paths)
Date: Sat, 21 Jun 2008 07:54:35 +0000 (UTC)

 1.1

*ix vets should know this already, but I was thinking about it again 
today, wondering how many sysadmin (and every Gentoo system user with 
root access is effectively a sysadmin) newbies know it, thus this post.

No untrusted or non-root user should be able to set the path for root, or 
write to any directories found in that path.  If they can, or can 
otherwise convince a root user to run an executable that they can write 
to, they effectively already have root.

Something to think about when you are running as root.  Do you ever as 
root run scripts or other executables that a user has write access to?  
Are your system permissions and root path setup appropriately so you 
can't run them by default, perhaps when someone puts their own version of 
something like ls earlier in your path than the system version?  

Some cautious admins make it a practice to always use a full path when 
invoking a command as root.  That's a good practice, as far as it goes, 
but to be really effective, they must ensure no scripts or other commands 
they run as root, invoke anything else without full path either.  That's 
a tough one, even tougher than teaching yourself to always use a full 
path, so not so many bother.

Who knows, maybe this will prevent someone reading it from getting 
rooted.  Like I said, I was just thinking about it, and decided it might 
be something worth posting.

-- 
Duncan - List replies preferred.   No HTML msgs.
"Every nonfree program has a lord, a master --
and if you use the program, he is your master."  Richard Stallman

-- 
gentoo-amd64@g.o mailing list


Navigation:
Lists: gentoo-amd64: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Laptop freeze
Next by thread:
Kernel 2.6.25
Previous by date:
Re: Re: Laptop freeze
Next by date:
Re: Re: Laptop freeze


Oct 15, 2008

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.