Gentoo Archives: gentoo-dev

From: Frank Groeneveld <frankgroeneveld@×××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] /sbin /usr/sbin security hole
Date: Tue, 17 Jan 2006 13:43:28
Message-Id: 43CCF3D7.604@gmail.com
In Reply to: [gentoo-dev] /sbin /usr/sbin security hole by "Paweł Madej"
1 Hi,
2
3 You probably have /sbin/shutdown set suid, because on all my Gentoo
4 boxes, normal users can't run it, only root can run it. (Permission
5 denied). What is the output of ls -al /sbin/?
6
7 Greets,
8 Frank
9
10 Paweł Madej wrote:
11 > -----BEGIN PGP SIGNED MESSAGE-----
12 > Hash: SHA1
13 >
14 > Hello,
15 >
16 > Today i've noticed that common user do not have /sbin and /usr/sbin dirs
17 > in their PATH but they can start all the tasks from that directories for
18 > example on server machine someone could make /sbin/shutdown and turn the
19 > server off. For me it is very big security hole.
20 >
21 > Maybe it has to be set like that, maybe I'm wrong, but if so please tell
22 > me why.
23 >
24 >
25 > - --
26 > Paweł Madej aka Nysander
27 > Member of QuanTeam | RLU #357047
28 > http://wiki.quanteam.info | Gentoo Linux User
29 > http://forum-farmaceutyczne.org | GPG key: 5861680B
30 > | keyserver: http://pgp.mit.edu
31 > Kielce, Poland | UTF-8 Email Preferred
32 >
33 > Looking to buy: 6x 73 GB UW3/Ultra160 SCSI 80 pin (SCA)
34 > ..::||::.. pair of PentiumIII Slot1 1GHz/ FSB 100 processors
35 > ..::||::.. 2x 256 MB SDRAM ECC Registered
36 > Got any of this mail me, with prize and shipping costs.
37 > -----BEGIN PGP SIGNATURE-----
38 > Version: GnuPG v1.4.2 (GNU/Linux)
39 >
40 > iD8DBQFDzO4vgvSMglhhaAsRAid1AJ9UU8uKgDmXVzGWCu+wtiCsutvg3wCeODEQ
41 > WNtJXfOxciZCwNB/UwmtLyQ=
42 > =hMHo
43 > -----END PGP SIGNATURE-----
44 >
45 --
46 gentoo-dev@g.o mailing list

Replies

Subject Author
Re: [gentoo-dev] /sbin /usr/sbin security hole Darryl Wagoner <darryl-prv@××××××××.net>
Re: [gentoo-dev] /sbin /usr/sbin security hole "Paweł Madej" <linux@××××××××.info>