Gentoo Archives: gentoo-dev

From: "Paweł Madej" <linux@××××××××.info>
To: gentoo-dev@l.g.o
Subject: [gentoo-dev] /sbin /usr/sbin security hole
Date: Tue, 17 Jan 2006 13:28:28
Message-Id: 43CCEE7E.5050906@quanteam.info
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Hello,
5
6 Today i've noticed that common user do not have /sbin and /usr/sbin dirs
7 in their PATH but they can start all the tasks from that directories for
8 example on server machine someone could make /sbin/shutdown and turn the
9 server off. For me it is very big security hole.
10
11 Maybe it has to be set like that, maybe I'm wrong, but if so please tell
12 me why.
13
14
15 - --
16 Paweł Madej aka Nysander
17 Member of QuanTeam | RLU #357047
18 http://wiki.quanteam.info | Gentoo Linux User
19 http://forum-farmaceutyczne.org | GPG key: 5861680B
20 | keyserver: http://pgp.mit.edu
21 Kielce, Poland | UTF-8 Email Preferred
22
23 Looking to buy: 6x 73 GB UW3/Ultra160 SCSI 80 pin (SCA)
24 ..::||::.. pair of PentiumIII Slot1 1GHz/ FSB 100 processors
25 ..::||::.. 2x 256 MB SDRAM ECC Registered
26 Got any of this mail me, with prize and shipping costs.
27 -----BEGIN PGP SIGNATURE-----
28 Version: GnuPG v1.4.2 (GNU/Linux)
29
30 iD8DBQFDzO4vgvSMglhhaAsRAid1AJ9UU8uKgDmXVzGWCu+wtiCsutvg3wCeODEQ
31 WNtJXfOxciZCwNB/UwmtLyQ=
32 =hMHo
33 -----END PGP SIGNATURE-----
34
35 --
36 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] /sbin /usr/sbin security hole Frank Groeneveld <frankgroeneveld@×××××.com>
Re: [gentoo-dev] /sbin /usr/sbin security hole Brian Harring <ferringb@g.o>