Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #178198

Re: Security hole in LXDE?

From Joe <joe@jretrading.com>
Newsgroups linux.debian.user
Subject Re: Security hole in LXDE?
Date 2017-02-27 12:50 +0100
Message-ID <tfrYu-4Xq-3@gated-at.bofh.it> (permalink)
References <tfpMZ-3yz-1@gated-at.bofh.it> <tfrlM-4I3-11@gated-at.bofh.it> <tfrF7-4Ql-25@gated-at.bofh.it>
Organization JRE Trading Ltd

Show all headers | View raw


On Mon, 27 Feb 2017 12:20:50 +0100
Hans <hans.ullrich@loop.de> wrote:

> > Check how synaptic is being started by the menu entry. Typically,
> > synaptic will be started by /usr/bin/synaptic-pkexec, which uses
> > policykit to authorise an effective su for a normal user. The
> > executable synaptic is in /usr/sbin, so will probably not work from
> > a menu.  
> 
> Yes, it is as you said. There is /usr/bin/synaptic-pkexec
> and /usr/sbin/synatic
> 
> > 
> > I've changed the launcher to gksudo synaptic, which gives me
> > explicit fine control with sudoers.
> >   
> 
> As I said: I do NOT use sudoers, and there is no entry or the
> user /etc/ sudoers. 
> 
> > I suspect what you're seeing is as intended.  
> 
> If so, then why not working so in KDE? And if this is intended, then
> this is a bug and a security hole, which should be fixed.
> 

I use neither LXDE nor KDE, so I would be guessing, but generally menu
operation is a function of the desktop environment, and the KDE menu
call may not be using pkexec. Or it may be using pkexec, but with a
different policy in action.

I have the common problem of using an old installation, with no
recollection of the changes I have made over years to the default
settings. For as long as I can remember, I have intended to log every
change I make, and one day perhaps I will begin...

-- 
Joe

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 10:30 +0100
  Re: Security hole in LXDE? Jonathan Dowland <jmtd@debian.org> - 2017-02-27 11:00 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:20 +0100
      Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 16:40 +0100
      Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 11:50 +0100
        Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 12:40 +0100
          Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 13:20 +0100
            Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 14:20 +0100
              Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 14:40 +0100
                Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:20 +0100
              Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-03-02 15:10 +0100
                Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:40 +0100
      [SOLVED] Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-06 18:30 +0100
        Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 19:40 +0100
          Re: [SOLVED] Re: Security hole in LXDE? Greg Wooledge <wooledg@eeg.ccf.org> - 2017-03-06 19:50 +0100
            Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 20:00 +0100
              Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 20:40 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 21:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Curt <curty@free.fr> - 2017-03-06 21:50 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 22:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 22:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-07 13:10 +0100
            Re: [SOLVED] Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-06 20:50 +0100
  Re: Security hole in LXDE? Davor Balder <davor@cropakglobal.com> - 2017-02-27 11:10 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:30 +0100
      Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 12:20 +0100
        Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-27 23:00 +0100
          Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-28 11:10 +0100
            Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
          Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-28 13:40 +0100
            Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
              Re: Security hole in LXDE? Lisi Reisz <lisi.reisz@gmail.com> - 2017-03-01 01:00 +0100
    Re: Security hole in LXDE? cbannister@slingshot.co.nz - 2017-03-25 07:20 +0100
  Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:10 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 12:30 +0100
      Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:50 +0100
      Re: Security hole in LXDE? Pontus Goffe <goffe.pontus@gmail.com> - 2017-02-27 15:50 +0100

csiph-web