Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #178187 > unrolled thread

Security hole in LXDE?

Started byHans <hans.ullrich@loop.de>
First post2017-02-27 10:30 +0100
Last post2017-02-27 15:50 +0100
Articles 19 on this page of 39 — 13 participants

Back to article view | Back to linux.debian.user


Contents

  Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 10:30 +0100
    Re: Security hole in LXDE? Jonathan Dowland <jmtd@debian.org> - 2017-02-27 11:00 +0100
      Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:20 +0100
        Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 16:40 +0100
        Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 11:50 +0100
          Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 12:40 +0100
            Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 13:20 +0100
              Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 14:20 +0100
                Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 14:40 +0100
                  Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:20 +0100
                Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-03-02 15:10 +0100
                  Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:40 +0100
        [SOLVED] Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-06 18:30 +0100
          Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 19:40 +0100
            Re: [SOLVED] Re: Security hole in LXDE? Greg Wooledge <wooledg@eeg.ccf.org> - 2017-03-06 19:50 +0100
              Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 20:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 20:40 +0100
                  Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 21:00 +0100
                    Re: [SOLVED] Re: Security hole in LXDE? Curt <curty@free.fr> - 2017-03-06 21:50 +0100
                      Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 22:00 +0100
                        Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
                    Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 22:00 +0100
                      Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
                        Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-07 13:10 +0100
              Re: [SOLVED] Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-06 20:50 +0100
    Re: Security hole in LXDE? Davor Balder <davor@cropakglobal.com> - 2017-02-27 11:10 +0100
      Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:30 +0100
        Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 12:20 +0100
          Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-27 23:00 +0100
            Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-28 11:10 +0100
              Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
            Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-28 13:40 +0100
              Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
                Re: Security hole in LXDE? Lisi Reisz <lisi.reisz@gmail.com> - 2017-03-01 01:00 +0100
      Re: Security hole in LXDE? cbannister@slingshot.co.nz - 2017-03-25 07:20 +0100
    Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:10 +0100
      Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 12:30 +0100
        Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:50 +0100
        Re: Security hole in LXDE? Pontus Goffe <goffe.pontus@gmail.com> - 2017-02-27 15:50 +0100

Page 2 of 2 — ← Prev page 1 [2]


#178522 — Re: [SOLVED] Re: Security hole in LXDE?

From<tomas@tuxteam.de>
Date2017-03-07 09:10 +0100
SubjectRe: [SOLVED] Re: Security hole in LXDE?
Message-ID<tiilY-4E4-7@gated-at.bofh.it>
In reply to#178508
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Mar 06, 2017 at 08:58:25PM +0000, Joe wrote:

[...]

> A member of the sudo group has permanent root privileges. He might as
> well simply login as root every day, and not bother with another user.

Sorry, I've to disagree. It's a question of ergonomics. To some people
(may be not for you, and that's fine) it does make a difference to have
to invoke sudo and being prompted for a password (e.g. raise the level
of awareness, notice when an obscure app is trying to gain privileges,
whatever).

I switched from a su oriented setup to a sudo oriented setup many moons
ago and the ergonomy WorksForMe.

Stating things in as an absolute way as you did above is almost always
wrong. Or: All generalizations suck ;-)

> My understanding of the use of the sudo group was for multiple server
> admins, not workstation users.

Why that?

My only beef with the general exodus to sudo is that some (I think
the first was Ubuntu) thought you could do away with root password.
Until... you are in front of a box where the root file system check
failed and it prompts you for the root password for rescue. Sudo?
HAH.

Again: all absolutes are wrong, as I said :-)

regards
- -- t
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAli+aS8ACgkQBcgs9XrR2kbCEgCdFZOKtyuroWvHTKgJc1VZVNk6
sf0AnRpLBaAfOQGFbRkwJkTvo4ryBaC7
=BeJ3
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#178507 — Re: [SOLVED] Re: Security hole in LXDE?

FromBrian <ad44@cityscape.co.uk>
Date2017-03-06 22:00 +0100
SubjectRe: [SOLVED] Re: Security hole in LXDE?
Message-ID<ti7TA-5e3-9@gated-at.bofh.it>
In reply to#178505
On Mon 06 Mar 2017 at 19:57:25 +0000, Joe wrote:

> On Mon, 6 Mar 2017 19:36:40 +0000
> Brian <ad44@cityscape.co.uk> wrote:
> 
> > On Mon 06 Mar 2017 at 18:59:18 +0000, Joe wrote:
> > 
> > > On Mon, 6 Mar 2017 13:40:45 -0500
> > > Greg Wooledge <wooledg@eeg.ccf.org> wrote:
> > >   
> > > > On Mon, Mar 06, 2017 at 06:31:46PM +0000, Joe wrote:  
> > > > > Debian appears to use the group 'sudo' as an administrative
> > > > > group, where some other distributions use 'wheel'.
> > > > > 
> > > > > I would not have thought that users would be added to it by
> > > > > default, there are no members on my sid/xfce4 workstation.
> > > > > Indeed, up to Jessie, sudo was not installed at all by default,
> > > > > and may still not be.    
> > > > 
> > > > If you use the regular Debian installer, the user account that you
> > > > create during installation gets added to a lot of these special
> > > > groups (sudo, cdrom, floppy, audio, video, ...?).  Users that you
> > > > create post-installtion using adduser or useradd do not.
> > > >   
> > > 
> > > New behaviour, then, my current sid was installed as wheezy, I added
> > > sudo manually early on, but as it was not installed by default, it
> > > would not have added the installing user to a sudo group. I'm
> > > certainly not a member of that group, and have no wish to be.  
> > 
> > The "first user" is not in the sudo group. The place to check this
> > is the templates file in the user-setup-udeb package.
> >  
> > > Possibly I'm missing something, but doesn't this repeat the Windows
> > > mistake of automatically giving the user admin privileges? Isn't
> > > that the main reason for the existence of so many Windows viruses?  
> > 
> > Look at it this way. The "first user" wishes to set up a printer. Is
> > it better for the user to be granted very limited privileges by being
> > in the lpadmin group or to become root to carry out the task?
> > 
> 
> Who said anything about lpadmin? The question is about the wisdom of
> automatically including someone in the sudo group, which in a default
> Debian sudoers file, gives full root privileges to everything, using the
> user's password.
>
> We have someone saying this happens, someone else saying it doesn't, I
> don't know as I haven't done a recent installation, and the thread was
> started by someone who says it did happen to him.

I'll reconstruct my previous response. If there is no root password,
sudo is installed and the "first user" is put into the sudo group.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#178521 — Re: [SOLVED] Re: Security hole in LXDE?

From<tomas@tuxteam.de>
Date2017-03-07 09:10 +0100
SubjectRe: [SOLVED] Re: Security hole in LXDE?
Message-ID<tiilY-4E4-5@gated-at.bofh.it>
In reply to#178507
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mon, Mar 06, 2017 at 08:53:39PM +0000, Brian wrote:

[...]

> I'll reconstruct my previous response. If there is no root password,

(a bad idea, see my other post)

> sudo is installed and the "first user" is put into the sudo group.

I've no proof for that, but yes, that corresponds to my experience
(in a somewhat fuzzy, mushy sense).

Regards
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAli+aa8ACgkQBcgs9XrR2kbv4ACff9GeeScZgZHryA6FtYQzInnz
gQUAn0Mjt3YsQ6dcnuSPspmTtc+I5xaR
=mZT6
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#178530 — Re: [SOLVED] Re: Security hole in LXDE?

FromBrian <ad44@cityscape.co.uk>
Date2017-03-07 13:10 +0100
SubjectRe: [SOLVED] Re: Security hole in LXDE?
Message-ID<tim6d-7io-1@gated-at.bofh.it>
In reply to#178521
On Tue 07 Mar 2017 at 09:05:03 +0100, tomas@tuxteam.de wrote:

> On Mon, Mar 06, 2017 at 08:53:39PM +0000, Brian wrote:
> 
> [...]
> 
> > I'll reconstruct my previous response. If there is no root password,
> 
> (a bad idea, see my other post)
> 
> > sudo is installed and the "first user" is put into the sudo group.
> 
> I've no proof for that, but yes, that corresponds to my experience
> (in a somewhat fuzzy, mushy sense).

Obtain the proof, then. I'll mention the user-setup-udeb package again.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#178504 — Re: [SOLVED] Re: Security hole in LXDE?

FromGiaThnYgeia <GiaThnYgeia@openmailbox.org>
Date2017-03-06 20:50 +0100
SubjectRe: [SOLVED] Re: Security hole in LXDE?
Message-ID<ti6NS-4s3-77@gated-at.bofh.it>
In reply to#178501
Greg Wooledge:
> On Mon, Mar 06, 2017 at 06:31:46PM +0000, Joe wrote:
>> Debian appears to use the group 'sudo' as an administrative group,
>> where some other distributions use 'wheel'.
>>
>> I would not have thought that users would be added to it by default,
>> there are no members on my sid/xfce4 workstation. Indeed, up to Jessie,
>> sudo was not installed at all by default, and may still not be.
> 
> If you use the regular Debian installer, the user account that you
> create during installation gets added to a lot of these special groups
> (sudo, cdrom, floppy, audio, video, ...?).  Users that you create
> post-installtion using adduser or useradd do not.

On an Debian-lxde installer you are asked for a root pass and then a
username/pass
As I remember before you manually add a user in the user group the sudo
command results to error.  Before I figured it out I had to use su
instead and any admin-package required user:root and pass to run.  After
adding a user in the sudo list all such packages ask for the user's
pass.  I think it is a sensible policy.

-- 
 "The most violent element in society is ignorance" rEG

[toc] | [prev] | [next] | [standalone]


#178190

FromDavor Balder <davor@cropakglobal.com>
Date2017-02-27 11:10 +0100
Message-ID<tfqpI-45z-17@gated-at.bofh.it>
In reply to#178187
Hi Hans,

Question 1 which one: stable, testing or unstable?

Generally (to aid in your investigation):

1.) It may be a good idea just to recheck your sudo settings first
(/etc/sudoers).

(relevant uncommented setting on this system:


##
## User privilege specification
##
root ALL=(ALL) ALL

2.) The other thing would be to check your regular user's group settings
(group memberships).

For example (on this system):

[davor@lucifer ~]$ groups davor
wheel plugdev users

Other than that, ensure you are not running as root (or sudo), ensure
you are updated, reboot and try again as regular user. LXDE is very
mature, this is unlikely to happen.


Cheers


D

On 27/02/17 20:19, Hans wrote:
> Hi folks,
>
> on my system /debian-amd64/testing) I can start Synaptic as a normal user, 
> just by using the user password. In KDE this is not possible, there I need the 
> root password.
>
> I do not have sudo in use.
>
> As I do not know, if this is a problem on my system (I have no second one to 
> confirm this)., maybe please someone else could check this.
>
> If I am correct, this is a security hole. If I am wrong, I have to recheck my 
> system.
>
> Thank you for your help.
>
> Best
>
> Hans
>

[toc] | [prev] | [next] | [standalone]


#178193

FromHans <hans.ullrich@loop.de>
Date2017-02-27 11:30 +0100
Message-ID<tfqJ4-4cn-17@gated-at.bofh.it>
In reply to#178190
Am Montag, 27. Februar 2017, 21:00:15 CET schrieb Davor Balder:
> Hi Hans,
> 
> Question 1 which one: stable, testing or unstable?

testing/amd64
> 
> Generally (to aid in your investigation):
> 
I did, but found nothing unusual. 

If no one can confirm this, it is a problem on my system!

Hans

[toc] | [prev] | [next] | [standalone]


#178195

FromGiaThnYgeia <GiaThnYgeia@openmailbox.org>
Date2017-02-27 12:20 +0100
Message-ID<tfrvs-4MR-3@gated-at.bofh.it>
In reply to#178193
testingAmd64LXDE

I have never, not once, been able to run synaptic in any similar system
without a root or a sudo password.  Not to execute a command, just to
get the gui up you need a password.

I don't know whether creating a user with 100% admin privileges will
still require a pass or not, I suspect it would still.  As if you add a
user in the sudo group it is the user's pass that is asked.  So
something is wrong on your specific installation.

Hans:
> Am Montag, 27. Februar 2017, 21:00:15 CET schrieb Davor Balder:
>> Hi Hans,
>>
>> Question 1 which one: stable, testing or unstable?
> 
> testing/amd64
>>
>> Generally (to aid in your investigation):
>>
> I did, but found nothing unusual. 
> 
> If no one can confirm this, it is a problem on my system!
> 
> Hans
> 

-- 
 "The most violent element in society is ignorance" rEG

[toc] | [prev] | [next] | [standalone]


#178236

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2017-02-27 23:00 +0100
Message-ID<tfBuO-38U-7@gated-at.bofh.it>
In reply to#178195
On Mon 27 Feb 2017 at 11:13:00 (+0000), GiaThnYgeia wrote:
> testingAmd64LXDE
> 
> I have never, not once, been able to run synaptic in any similar system
> without a root or a sudo password.  Not to execute a command, just to
> get the gui up you need a password.

Why would that be? You should be able to do so. There's a popup
window that says this:

  Starting "Synaptic Package Manager" without administrative privileges

  You will not be able to apply any changes, but you can still export
  the marked changes or create a download script for them.

I can select packages, look at their properties, dependencies,
installed files, get changelogs etc. I can edit some of the
preferences. I can see the immediate effects of that in files
like ~/.synaptic/synaptic.conf when I click OK. I can select
packages for installation and it will write a little script
for me:

 #!/bin/sh
 wget -c
 http://ftp.us.debian.org/debian/pool/non-free/i/ibm-3270/3270-common_3.3.14ga11-1_i386.deb

So it suggests that the OP has set something in their system
to cause the behaviour they observe, both the popup and the
fact that a user's password is sufficient for installing software.

I can run (the similar program) aptitude likewise. The main differences
with synaptic are that aptitude is in the user's normal PATH (whereas
synaptic is in /usr/sbin); when you try to install, it asks you to
consider becoming root from the Actions menu; and if you persist, it
gives you the option to become root in a dialog box, and you can then
type the root password.

> I don't know whether creating a user with 100% admin privileges will
> still require a pass or not, I suspect it would still.  As if you add a
> user in the sudo group it is the user's pass that is asked.  So
> something is wrong on your specific installation.
> 
> Hans:
> > Am Montag, 27. Februar 2017, 21:00:15 CET schrieb Davor Balder:
> >> Hi Hans,
> >>
> >> Question 1 which one: stable, testing or unstable?
> > 
> > testing/amd64
> >>
> >> Generally (to aid in your investigation):
> >>
> > I did, but found nothing unusual. 
> > 
> > If no one can confirm this, it is a problem on my system!

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#178252

FromHans <hans.ullrich@loop.de>
Date2017-02-28 11:10 +0100
Message-ID<tfMTg-2Zb-15@gated-at.bofh.it>
In reply to#178236
I am not sure, if I some day allowed the normal user to start synaptic as a 
normal user. Sometimes this option is offered at the first start.

If I have done this (which I was at that moment wiling to do), where do I have 
to look, to make this thing back to normal?

Please note, that I am not using sudoers, but I am sure, I am using either 
kdesu or gksudo. As I am a mostly using KDE, I bet, kdesu is the one, where I 
might have to look for as IMO this one is the thing, that might be responsible 
for the rights.  But where do I have to look then? 

Thanks for any hints.

Best

Hans

[toc] | [prev] | [next] | [standalone]


#178283

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2017-02-28 18:50 +0100
Message-ID<tfU4q-7JC-19@gated-at.bofh.it>
In reply to#178252
On Tue 28 Feb 2017 at 11:02:14 (+0100), Hans wrote:
> I am not sure, if I some day allowed the normal user to start synaptic as a 
> normal user. Sometimes this option is offered at the first start.

I wouldn't know how to _prevent_ and ordinary user from running
synaptic by typing /usr/sbin/synaptic, unless you had them running in
some sort of restricted shall. Synaptic is obviously designed to be
run by unprivileged users which is why it has that dialog box warning.

> If I have done this (which I was at that moment wiling to do), where do I have 
> to look, to make this thing back to normal?
> 
> Please note, that I am not using sudoers, but I am sure, I am using either 
> kdesu or gksudo. As I am a mostly using KDE, I bet, kdesu is the one, where I 
> might have to look for as IMO this one is the thing, that might be responsible 
> for the rights.  But where do I have to look then? 

Yes, I agree that the clue is in your DE. I'm a WM person (fvwm)
and use sudoers for allowing me to do a few things like kicking
exim and changing timezones. Joe and Pontus may be more help
in at least having the configuration files to look at.

My assumption would be to look at the DE's configuration in
/etc as you wouldn't expect a user to be able to confer this privilege
on themselves. Are you user 1000? Did you gain privileges merely
through being the first user at installation time? Could that be
normal? Not for Pontus it seems.

Just as, by default, you can gain privileges by being the person
seated at the computer, so it might make some sort of sense for the
first user to have certain privileges granted to them for
administrating the DE. After all, you wouldn't want to run X as
root, let alone a whole DE. My own working practice is a root
shell inside an xterm (and my tools aren't gui), but that doesn't
fit with how a DE runs things. I assume your problem lies in a
helper, which picks up privileges, somewhere between the icon
(or menu choice) and the synaptic binary itself. How it might have
got changed, I don't know.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#178259

FromGiaThnYgeia <GiaThnYgeia@openmailbox.org>
Date2017-02-28 13:40 +0100
Message-ID<tfPer-4pW-31@gated-at.bofh.it>
In reply to#178236
As a user and as I understand it you should not be able to make
system-wide changes and many packages affect other parts of the system.
A user can install and run any package that does not affect the system,
as a stand alone.  The system is a whole must be maintained by the
sysadmin for all users.  That is my simplistic understanding.
Unless it is specifically configured otherwise I don't see why these
assumptions would be wrong.  Imagine if I like MATE and the other user
likes X11 and I delete x11 and install MATE, or I install a package that
has dependency conflicts and replaces what is essential for the other
users' packages.

Live systems allow you to install whatever you like as they assume you
are the root or sysadmin.

At least that is how I understand security policy for this system.

David Wright:
> On Mon 27 Feb 2017 at 11:13:00 (+0000), GiaThnYgeia wrote:
>> testingAmd64LXDE
>>
>> I have never, not once, been able to run synaptic in any similar system
>> without a root or a sudo password.  Not to execute a command, just to
>> get the gui up you need a password.
> 
> Why would that be? You should be able to do so. There's a popup
> window that says this:
> 
>   Starting "Synaptic Package Manager" without administrative privileges
> 
>   You will not be able to apply any changes, but you can still export
>   the marked changes or create a download script for them.
> 
> I can select packages, look at their properties, dependencies,
> installed files, get changelogs etc. I can edit some of the
> preferences. I can see the immediate effects of that in files
> like ~/.synaptic/synaptic.conf when I click OK. I can select
> packages for installation and it will write a little script
> for me:
> 
>  #!/bin/sh
>  wget -c
>  http://ftp.us.debian.org/debian/pool/non-free/i/ibm-3270/3270-common_3.3.14ga11-1_i386.deb
> 
> So it suggests that the OP has set something in their system
> to cause the behaviour they observe, both the popup and the
> fact that a user's password is sufficient for installing software.
> 
> I can run (the similar program) aptitude likewise. The main differences
> with synaptic are that aptitude is in the user's normal PATH (whereas
> synaptic is in /usr/sbin); when you try to install, it asks you to
> consider becoming root from the Actions menu; and if you persist, it
> gives you the option to become root in a dialog box, and you can then
> type the root password.
> 
>> I don't know whether creating a user with 100% admin privileges will
>> still require a pass or not, I suspect it would still.  As if you add a
>> user in the sudo group it is the user's pass that is asked.  So
>> something is wrong on your specific installation.
>>
>> Hans:
>>> Am Montag, 27. Februar 2017, 21:00:15 CET schrieb Davor Balder:
>>>> Hi Hans,
>>>>
>>>> Question 1 which one: stable, testing or unstable?
>>>
>>> testing/amd64
>>>>
>>>> Generally (to aid in your investigation):
>>>>
>>> I did, but found nothing unusual. 
>>>
>>> If no one can confirm this, it is a problem on my system!
> 
> Cheers,
> David.
> 

-- 
 "The most violent element in society is ignorance" rEG

[toc] | [prev] | [next] | [standalone]


#178281

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2017-02-28 18:50 +0100
Message-ID<tfU4q-7JC-15@gated-at.bofh.it>
In reply to#178259
On Tue 28 Feb 2017 at 12:31:00 (+0000), GiaThnYgeia wrote:
> As a user and as I understand it you should not be able to make
> system-wide changes and many packages affect other parts of the system.
> A user can install and run any package that does not affect the system,
> as a stand alone.  The system is a whole must be maintained by the
> sysadmin for all users.  That is my simplistic understanding.
> Unless it is specifically configured otherwise I don't see why these
> assumptions would be wrong.  Imagine if I like MATE and the other user
> likes X11 and I delete x11 and install MATE, or I install a package that
> has dependency conflicts and replaces what is essential for the other
> users' packages.
> 
> Live systems allow you to install whatever you like as they assume you
> are the root or sysadmin.
> 
> At least that is how I understand security policy for this system.

Apart from not understanding what you mean by "installing packages as
a stand alone", that all looks fine. My post merely demonstrated that
synaptic is not unusual in being runnable by ordinary users. So your
inability, and the need for a password, lies outside synaptic and in
the realm of the DE, which set up the icon or menu that you use to
the exclusion of other methods. In a sense my post was just a gloss
on Jonathan Dowland's post.

So why did I comment on _your_ post? Only days ago, I mentioned
someone's old d-u assertions that you couldn't run aptitude as an
ordinary user, which is not true. I didn't want your statement to
give people the same false impression anout synaptic, especially
as that someone uses synaptic.

Both aptitude and synaptic can run by an ordinary user, and it's a
very safe way to run them when you don't yet fully understand their
abilities.

> David Wright:
> > On Mon 27 Feb 2017 at 11:13:00 (+0000), GiaThnYgeia wrote:
> >> testingAmd64LXDE
> >>
> >> I have never, not once, been able to run synaptic in any similar system
> >> without a root or a sudo password.  Not to execute a command, just to
> >> get the gui up you need a password.
> > 
> > Why would that be? You should be able to do so. There's a popup
> > window that says this:
> > 
> >   Starting "Synaptic Package Manager" without administrative privileges
> > 
> >   You will not be able to apply any changes, but you can still export
> >   the marked changes or create a download script for them.
> > 
> > I can select packages, look at their properties, dependencies,
> > installed files, get changelogs etc. I can edit some of the
> > preferences. I can see the immediate effects of that in files
> > like ~/.synaptic/synaptic.conf when I click OK. I can select
> > packages for installation and it will write a little script
> > for me:
> > 
> >  #!/bin/sh
> >  wget -c
> >  http://ftp.us.debian.org/debian/pool/non-free/i/ibm-3270/3270-common_3.3.14ga11-1_i386.deb
> > 
> > So it suggests that the OP has set something in their system
> > to cause the behaviour they observe, both the popup and the
> > fact that a user's password is sufficient for installing software.
> > 
> > I can run (the similar program) aptitude likewise. The main differences
> > with synaptic are that aptitude is in the user's normal PATH (whereas
> > synaptic is in /usr/sbin); when you try to install, it asks you to
> > consider becoming root from the Actions menu; and if you persist, it
> > gives you the option to become root in a dialog box, and you can then
> > type the root password.
> > 
> >> I don't know whether creating a user with 100% admin privileges will
> >> still require a pass or not, I suspect it would still.  As if you add a
> >> user in the sudo group it is the user's pass that is asked.  So
> >> something is wrong on your specific installation.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#178305

FromLisi Reisz <lisi.reisz@gmail.com>
Date2017-03-01 01:00 +0100
Message-ID<tfZQu-2Vc-21@gated-at.bofh.it>
In reply to#178281
On Tuesday 28 February 2017 17:45:57 David Wright wrote:
> Both aptitude and synaptic can run by an ordinary user, and it's a
> very safe way to run them when you don't yet fully understand their
> abilities.

To extend for the sake of pedantic ultra-clarity, and not to contradict:  
aptitude can be run as an ordinary user, but you cannot change anything as an 
ordinary user - only look at what is there.  To change anything, e.g. install 
or uninstall  something, you must have root privileges.

Lisi

[toc] | [prev] | [next] | [standalone]


#179296

Fromcbannister@slingshot.co.nz
Date2017-03-25 07:20 +0100
Message-ID<toNdn-5gr-1@gated-at.bofh.it>
In reply to#178190
On Mon, Feb 27, 2017 at 09:00:15PM +1100, Davor Balder wrote:
> Hi Hans,
> 
> Question 1 which one: stable, testing or unstable?

IMHO if it's not stated then stable is to be assumed.

Users who run testing/sid are generally expected to have
some degree of troubleshooting knowledge (the clue is in the
name.) Unfortunately, it appears that bad advice is given to
run testing or sid just because a user wants a later version
of a piece of software.

So sure, if a user is running testing/sid then you'd expect
that it would be stated early on in the post and that the
user has a reasonable amount of troubleshooting knowledge, and
has therefore experienced a 'special' case that someone else
may have a clue about.

So in a nutshell, only experienced users should be running
testing/sid and therefore any posts where the dist isn't
mentioned should be assumed that the user is running stable.

-- 
The media's the most powerful entity on earth. 
They have the power to make the innocent guilty 
and to make the guilty innocent, and that's power.
 -- Malcolm X

[toc] | [prev] | [next] | [standalone]


#178194

FromJoe <joe@jretrading.com>
Date2017-02-27 12:10 +0100
Message-ID<tfrlM-4I3-11@gated-at.bofh.it>
In reply to#178187
On Mon, 27 Feb 2017 10:19:47 +0100
Hans <hans.ullrich@loop.de> wrote:

> Hi folks,
> 
> on my system /debian-amd64/testing) I can start Synaptic as a normal
> user, just by using the user password. In KDE this is not possible,
> there I need the root password.
> 
> I do not have sudo in use.
> 
> As I do not know, if this is a problem on my system (I have no second
> one to confirm this)., maybe please someone else could check this.
> 
> If I am correct, this is a security hole. If I am wrong, I have to
> recheck my system.
> 
>

Check how synaptic is being started by the menu entry. Typically,
synaptic will be started by /usr/bin/synaptic-pkexec, which uses
policykit to authorise an effective su for a normal user. The executable
synaptic is in /usr/sbin, so will probably not work from a menu.

I've changed the launcher to gksudo synaptic, which gives me explicit
fine control with sudoers.

I suspect what you're seeing is as intended.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#178196

FromHans <hans.ullrich@loop.de>
Date2017-02-27 12:30 +0100
Message-ID<tfrF7-4Ql-25@gated-at.bofh.it>
In reply to#178194
> Check how synaptic is being started by the menu entry. Typically,
> synaptic will be started by /usr/bin/synaptic-pkexec, which uses
> policykit to authorise an effective su for a normal user. The executable
> synaptic is in /usr/sbin, so will probably not work from a menu.

Yes, it is as you said. There is /usr/bin/synaptic-pkexec
and /usr/sbin/synatic

> 
> I've changed the launcher to gksudo synaptic, which gives me explicit
> fine control with sudoers.
> 

As I said: I do NOT use sudoers, and there is no entry or the user /etc/
sudoers. 

> I suspect what you're seeing is as intended.

If so, then why not working so in KDE? And if this is intended, then this is a 
bug and a security hole, which should be fixed.

Hans

[toc] | [prev] | [next] | [standalone]


#178198

FromJoe <joe@jretrading.com>
Date2017-02-27 12:50 +0100
Message-ID<tfrYu-4Xq-3@gated-at.bofh.it>
In reply to#178196
On Mon, 27 Feb 2017 12:20:50 +0100
Hans <hans.ullrich@loop.de> wrote:

> > Check how synaptic is being started by the menu entry. Typically,
> > synaptic will be started by /usr/bin/synaptic-pkexec, which uses
> > policykit to authorise an effective su for a normal user. The
> > executable synaptic is in /usr/sbin, so will probably not work from
> > a menu.  
> 
> Yes, it is as you said. There is /usr/bin/synaptic-pkexec
> and /usr/sbin/synatic
> 
> > 
> > I've changed the launcher to gksudo synaptic, which gives me
> > explicit fine control with sudoers.
> >   
> 
> As I said: I do NOT use sudoers, and there is no entry or the
> user /etc/ sudoers. 
> 
> > I suspect what you're seeing is as intended.  
> 
> If so, then why not working so in KDE? And if this is intended, then
> this is a bug and a security hole, which should be fixed.
> 

I use neither LXDE nor KDE, so I would be guessing, but generally menu
operation is a function of the desktop environment, and the KDE menu
call may not be using pkexec. Or it may be using pkexec, but with a
different policy in action.

I have the common problem of using an old installation, with no
recollection of the changes I have made over years to the default
settings. For as long as I can remember, I have intended to log every
change I make, and one day perhaps I will begin...

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#178209

FromPontus Goffe <goffe.pontus@gmail.com>
Date2017-02-27 15:50 +0100
Message-ID<tfuMH-6Wf-31@gated-at.bofh.it>
In reply to#178196

Den 2017-02-27 kl. 12:20, skrev Hans:
> If so, then why not working so in KDE? And if this is intended, then this is a
> bug and a security hole, which should be fixed.
>
> Hans
>
A fresh vanilla install of testing with LXDE installs both sudo and 
gksu. Without configuring any, starting synaptic from menu prompts for 
the root password.
//PG

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | linux.debian.user


csiph-web