Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #268562
| Path | csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod |
|---|---|
| From | Lee <ler762@gmail.com> |
| Newsgroups | linux.debian.user |
| Subject | Re: making Debian secure by default |
| Date | Thu, 28 Mar 2024 05:30:01 +0100 |
| Message-ID | <ImPyN-2bh9-3@gated-at.bofh.it> (permalink) |
| References | <ImJa1-27aa-1@gated-at.bofh.it> <ImKz7-28aw-1@gated-at.bofh.it> |
| X-Mailbox-Line | From debian-user-request@lists.debian.org Thu Mar 28 04:29:32 2024 |
| Old-Return-Path | <ler762@gmail.com> |
| X-Amavis-Spam-Status | No, score=-6.949 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, LDO_WHITELIST=-5, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=ham autolearn_force=no |
| X-Policyd-Weight | NOT_IN_SBL_XBL_SPAMHAUS=-1.5 CL_IP_EQ_HELO_IP=-2 (check from: .gmail. - helo: .mail-il1-x131.google. - helo-domain: .google.) FROM/MX_MATCHES_HELO(DOMAIN)=-2; rate: -5.5 |
| X-Gm-Message-State | AOJu0YwIxS5cSbzJQYKZh1CADSd7uxAGydzKbk3a8067vvg8z2EvzX9n vGsGbCxDg2RI2uKtty1FbbQdTK7xa9zZTMtQpwbgzHbrUvQgKWgm7vL2jeRaJ8uUzBFV05Csc8X lyCREoLR7I0YjYr3n54wO4QXUzoelKcoBRkzUmQ== |
| X-Google-SMTP-Source | AGHT+IHsvMFyVCLfUrVT0EqVemjI0hFcknFgVjQyKf4i0odgsJCogwDy1wZBt5sz6q0igezNUZ3M74cooAb9rBSFVas= |
| X-Received | by 2002:a92:d210:0:b0:368:a637:96ad with SMTP id y16-20020a92d210000000b00368a63796admr1822519ily.32.1711600148720; Wed, 27 Mar 2024 21:29:08 -0700 (PDT) |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset="UTF-8" |
| Content-Transfer-Encoding | quoted-printable |
| X-Mailing-List | <debian-user@lists.debian.org> archive/latest/810518 |
| List-ID | <debian-user.lists.debian.org> |
| List-URL | <https://lists.debian.org/debian-user/> |
| List-Archive | https://lists.debian.org/msgid-search/CAD8GWsswLPH327tvj64HkWuMfayXczJyyviSk9Um2CAHHjoovg@mail.gmail.com |
| Approved | robomod@news.nic.it |
| Lines | 68 |
| Organization | linux.* mail to news gateway |
| Sender | robomod@news.nic.it |
| X-Original-Cc | debian-user@lists.debian.org |
| X-Original-Date | Thu, 28 Mar 2024 00:28:56 -0400 |
| X-Original-Message-ID | <CAD8GWsswLPH327tvj64HkWuMfayXczJyyviSk9Um2CAHHjoovg@mail.gmail.com> |
| X-Original-References | <CAD8GWssBoRrCzW0TSUGxMeuY=y_bTM-nMuSO7_4g1Kyk79fgqQ@mail.gmail.com> <ZgSljhflfCtsnnCq@mail.bitfolk.com> |
| Xref | csiph.com linux.debian.user:268562 |
Show key headers only | View raw
On Wed, Mar 27, 2024 at 10:07 PM Andy Smith wrote: > > Hi, > > On Wed, Mar 27, 2024 at 05:30:50PM -0400, Lee wrote: > > I just saw this advisory > > Escape sequence injection in util-linux wall (CVE-2024-28085) > > https://seclists.org/fulldisclosure/2024/Mar/35 > > where they're talking about grabbing other users sudo password. > > It doesn't work by default on Debian as it relies on > command-not-found automatically running on the user's input. > command-not-found can be installed, however… > > > oof. Are there instructions somewhere on how to make Debian secure by default? > > Between the fact that "secure" means different things to different > people and that this advisory was only released a few hours ago, I > don't think you can reasonably expect documentation to already be > published for your standard of "secure". You snipped the bit from the man page about users becoming more more conscious of various security risks & removing write access by default. Considering how long it takes something to migrate into stable I'm guessing that man page is pretty old. So I don't think it's unreasonable to expect some kind of secure by default installation option. > There is a general push to get rid of setuid/setgid binaries. A lot > of "hardening" guides will suggest looking for setuid/setgid > binaries and deciding if you really need them. The problem with that is how many users are knowledgeable enough to know if something is necessary or not? > As you've never heard of "mesg" and probably don't use "wall" I > doubt you will have any issues chmod 0 /usr/bin/wall and then > setting it immutable¹ with chattr +i. I suppose that's one way. I'd rather uninstall it. > You could put a call to "mesg n" into a file in /etc/profile.d so > that all users execute it. Good idea: $ ls -l /etc/profile.d/disable_mesg.sh -rw-r--r-- 1 root root 383 Mar 28 00:15 /etc/profile.d/disable_mesg.sh $ cat /etc/profile.d/disable_mesg.sh # man mesg # ... # Traditionally, write access is allowed by default. However, as users # become more conscious of various security risks, there is a trend to # remove write access by default, at least for the primary login shell. # To make sure your ttys are set the way you want them to be set, mesg # should be executed in your login scripts. /usr/bin/mesg n Then logout / login and.. $ mesg is n Thanks Lee
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
making Debian secure by default Lee <ler762@gmail.com> - 2024-03-27 22:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 00:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 05:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 14:40 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 16:30 +0100
Re: making Debian secure by default Hans <hans.ullrich@loop.de> - 2024-03-28 16:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 19:20 +0100
Re: making Debian secure by default Ralph Aichinger <ra@h5.or.at> - 2024-03-29 08:50 +0100
Re: making Debian secure by default Stefan Monnier <monnier@iro.umontreal.ca> - 2024-03-29 20:10 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-29 20:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 17:00 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 21:20 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-28 18:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 20:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 18:00 +0100
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-03-29 18:30 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 18:50 +0100
Re: making Debian secure by default Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-04-01 02:30 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-01 03:50 +0200
Re: making Debian secure by default Roberto C. Sánchez <roberto@debian.org> - 2024-04-01 05:00 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-01 10:40 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:50 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:51 +0200
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-06 09:50 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Nate Bargmann <n0nb@n0nb.us> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Charles Curley <charlescurley@charlescurley.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default John Hasler <john@sugarbit.com> - 2024-04-06 09:51 +0200
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default John Hasler <john@sugarbit.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Joe <joe@jretrading.com> - 2024-04-06 09:52 +0200
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 18:50 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-29 21:00 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-30 17:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 19:10 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-28 23:20 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Florent Rougon <f.rougon@free.fr> - 2024-03-28 18:10 +0100
Re: making Debian secure by default jeremy ardley <jeremy.ardley@gmail.com> - 2024-03-28 00:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 00:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 05:50 +0100
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-03-28 06:20 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-28 06:30 +0100
Re: making Debian secure by default <tomas@tuxteam.de> - 2024-03-28 08:20 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 12:20 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-28 12:40 +0100
Re: making Debian secure by default David Wright <deblis@lionunicorn.co.uk> - 2024-03-28 21:40 +0100
Re: making Debian secure by default Emanuel Berg <incal@dataswamp.org> - 2024-03-29 10:40 +0100
Re: making Debian secure by default David Wright <deblis@lionunicorn.co.uk> - 2024-03-30 04:00 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-28 15:50 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 18:10 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 21:50 +0100
Re: making Debian secure by default tomas@tuxteam.de - 2024-03-28 18:30 +0100
Re: making Debian secure by default Lee <ler762@gmail.com> - 2024-03-28 20:30 +0100
Re: making Debian secure by default Greg Wooledge <greg@wooledge.org> - 2024-03-28 20:30 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 21:50 +0100
Re: making Debian secure by default tomas@tuxteam.de - 2024-03-28 21:20 +0100
Re: making Debian secure by default Curt <curty@free.fr> - 2024-03-29 17:10 +0100
Re: making Debian secure by default debian-user@howorth.org.uk - 2024-03-29 21:50 +0100
Re: making Debian secure by default debian-user@howorth.org.uk - 2024-03-28 22:50 +0100
Re: making Debian secure by default Marc SCHAEFER <schaefer@alphanet.ch> - 2024-03-28 12:10 +0100
Re: making Debian secure by default Franco Martelli <martellif67@gmail.com> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Michel Verdier <mv524@free.fr> - 2024-03-28 17:30 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-28 17:40 +0100
Re: making Debian secure by default Michael Kjörling <2695bd53d63c@ewoof.net> - 2024-03-28 21:50 +0100
Re: making Debian secure by default Richmond <dnomhcir@gmx.com> - 2024-03-28 21:50 +0100
Re: making Debian secure by default Jeffrey Walton <noloader@gmail.com> - 2024-03-29 16:40 +0100
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-31 21:10 +0200
Re: making Debian secure by default Roberto C. Sánchez <roberto@debian.org> - 2024-03-31 21:30 +0200
Re: making Debian secure by default gene heskett <gheskett@shentel.net> - 2024-03-31 22:30 +0200
Re: making Debian secure by default Andy Smith <andy@strugglers.net> - 2024-03-31 23:20 +0200
Re: making Debian secure by default gene heskett <gheskett@shentel.net> - 2024-04-01 01:00 +0200
csiph-web