1 |
On Sun, Feb 28, 2010 at 7:28 AM, pk <peterk2@××××××××.se> wrote: |
2 |
> ubiquitous1980 wrote: |
3 |
> |
4 |
>>> http://lists.debian.org/debian-security/2006/07/msg00059.html |
5 |
> |
6 |
>> With "sudo su - " the man pages do not have ESC throughout. I have |
7 |
>> learned sudo su from my ubuntu days and I am only guessing that this is |
8 |
>> bad practice and that the correct command is $ sudo su - |
9 |
> |
10 |
> No need to guess. Messing with superuser privileges without a proper |
11 |
> superuser environment (paths etc.) is considered bad from a security |
12 |
> point of view; for instance, an malicious application could be installed |
13 |
> in your user home dir, prepend the path to this to your local user $PATH |
14 |
> and whenever you do "su" (without -) you could invoke this app with |
15 |
> superuser privileges... |
16 |
> So to summarize: The link above (debian.org) explains it quite well and |
17 |
> yes, I would say it's a bad habit to omit -. :-) |
18 |
|
19 |
7 years ago a veteran Linux user taught me to always use su - for the |
20 |
very reason you stated. |