Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #178187 > unrolled thread
| Started by | Hans <hans.ullrich@loop.de> |
|---|---|
| First post | 2017-02-27 10:30 +0100 |
| Last post | 2017-02-27 15:50 +0100 |
| Articles | 19 on this page of 39 — 13 participants |
Back to article view | Back to linux.debian.user
Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 10:30 +0100
Re: Security hole in LXDE? Jonathan Dowland <jmtd@debian.org> - 2017-02-27 11:00 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:20 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 16:40 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 11:50 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 12:40 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 13:20 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 14:20 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 14:40 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:20 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-03-02 15:10 +0100
Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:40 +0100
[SOLVED] Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-06 18:30 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 19:40 +0100
Re: [SOLVED] Re: Security hole in LXDE? Greg Wooledge <wooledg@eeg.ccf.org> - 2017-03-06 19:50 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 20:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 20:40 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 21:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? Curt <curty@free.fr> - 2017-03-06 21:50 +0100
Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 22:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 22:00 +0100
Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-07 13:10 +0100
Re: [SOLVED] Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-06 20:50 +0100
Re: Security hole in LXDE? Davor Balder <davor@cropakglobal.com> - 2017-02-27 11:10 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:30 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 12:20 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-27 23:00 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-28 11:10 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-28 13:40 +0100
Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
Re: Security hole in LXDE? Lisi Reisz <lisi.reisz@gmail.com> - 2017-03-01 01:00 +0100
Re: Security hole in LXDE? cbannister@slingshot.co.nz - 2017-03-25 07:20 +0100
Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:10 +0100
Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 12:30 +0100
Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:50 +0100
Re: Security hole in LXDE? Pontus Goffe <goffe.pontus@gmail.com> - 2017-02-27 15:50 +0100
Page 2 of 2 — ← Prev page 1 [2]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-03-07 09:10 +0100 |
| Subject | Re: [SOLVED] Re: Security hole in LXDE? |
| Message-ID | <tiilY-4E4-7@gated-at.bofh.it> |
| In reply to | #178508 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, Mar 06, 2017 at 08:58:25PM +0000, Joe wrote: [...] > A member of the sudo group has permanent root privileges. He might as > well simply login as root every day, and not bother with another user. Sorry, I've to disagree. It's a question of ergonomics. To some people (may be not for you, and that's fine) it does make a difference to have to invoke sudo and being prompted for a password (e.g. raise the level of awareness, notice when an obscure app is trying to gain privileges, whatever). I switched from a su oriented setup to a sudo oriented setup many moons ago and the ergonomy WorksForMe. Stating things in as an absolute way as you did above is almost always wrong. Or: All generalizations suck ;-) > My understanding of the use of the sudo group was for multiple server > admins, not workstation users. Why that? My only beef with the general exodus to sudo is that some (I think the first was Ubuntu) thought you could do away with root password. Until... you are in front of a box where the root file system check failed and it prompts you for the root password for rescue. Sudo? HAH. Again: all absolutes are wrong, as I said :-) regards - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAli+aS8ACgkQBcgs9XrR2kbCEgCdFZOKtyuroWvHTKgJc1VZVNk6 sf0AnRpLBaAfOQGFbRkwJkTvo4ryBaC7 =BeJ3 -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-03-06 22:00 +0100 |
| Subject | Re: [SOLVED] Re: Security hole in LXDE? |
| Message-ID | <ti7TA-5e3-9@gated-at.bofh.it> |
| In reply to | #178505 |
On Mon 06 Mar 2017 at 19:57:25 +0000, Joe wrote: > On Mon, 6 Mar 2017 19:36:40 +0000 > Brian <ad44@cityscape.co.uk> wrote: > > > On Mon 06 Mar 2017 at 18:59:18 +0000, Joe wrote: > > > > > On Mon, 6 Mar 2017 13:40:45 -0500 > > > Greg Wooledge <wooledg@eeg.ccf.org> wrote: > > > > > > > On Mon, Mar 06, 2017 at 06:31:46PM +0000, Joe wrote: > > > > > Debian appears to use the group 'sudo' as an administrative > > > > > group, where some other distributions use 'wheel'. > > > > > > > > > > I would not have thought that users would be added to it by > > > > > default, there are no members on my sid/xfce4 workstation. > > > > > Indeed, up to Jessie, sudo was not installed at all by default, > > > > > and may still not be. > > > > > > > > If you use the regular Debian installer, the user account that you > > > > create during installation gets added to a lot of these special > > > > groups (sudo, cdrom, floppy, audio, video, ...?). Users that you > > > > create post-installtion using adduser or useradd do not. > > > > > > > > > > New behaviour, then, my current sid was installed as wheezy, I added > > > sudo manually early on, but as it was not installed by default, it > > > would not have added the installing user to a sudo group. I'm > > > certainly not a member of that group, and have no wish to be. > > > > The "first user" is not in the sudo group. The place to check this > > is the templates file in the user-setup-udeb package. > > > > > Possibly I'm missing something, but doesn't this repeat the Windows > > > mistake of automatically giving the user admin privileges? Isn't > > > that the main reason for the existence of so many Windows viruses? > > > > Look at it this way. The "first user" wishes to set up a printer. Is > > it better for the user to be granted very limited privileges by being > > in the lpadmin group or to become root to carry out the task? > > > > Who said anything about lpadmin? The question is about the wisdom of > automatically including someone in the sudo group, which in a default > Debian sudoers file, gives full root privileges to everything, using the > user's password. > > We have someone saying this happens, someone else saying it doesn't, I > don't know as I haven't done a recent installation, and the thread was > started by someone who says it did happen to him. I'll reconstruct my previous response. If there is no root password, sudo is installed and the "first user" is put into the sudo group. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-03-07 09:10 +0100 |
| Subject | Re: [SOLVED] Re: Security hole in LXDE? |
| Message-ID | <tiilY-4E4-5@gated-at.bofh.it> |
| In reply to | #178507 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, Mar 06, 2017 at 08:53:39PM +0000, Brian wrote: [...] > I'll reconstruct my previous response. If there is no root password, (a bad idea, see my other post) > sudo is installed and the "first user" is put into the sudo group. I've no proof for that, but yes, that corresponds to my experience (in a somewhat fuzzy, mushy sense). Regards - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAli+aa8ACgkQBcgs9XrR2kbv4ACff9GeeScZgZHryA6FtYQzInnz gQUAn0Mjt3YsQ6dcnuSPspmTtc+I5xaR =mZT6 -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-03-07 13:10 +0100 |
| Subject | Re: [SOLVED] Re: Security hole in LXDE? |
| Message-ID | <tim6d-7io-1@gated-at.bofh.it> |
| In reply to | #178521 |
On Tue 07 Mar 2017 at 09:05:03 +0100, tomas@tuxteam.de wrote: > On Mon, Mar 06, 2017 at 08:53:39PM +0000, Brian wrote: > > [...] > > > I'll reconstruct my previous response. If there is no root password, > > (a bad idea, see my other post) > > > sudo is installed and the "first user" is put into the sudo group. > > I've no proof for that, but yes, that corresponds to my experience > (in a somewhat fuzzy, mushy sense). Obtain the proof, then. I'll mention the user-setup-udeb package again. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | GiaThnYgeia <GiaThnYgeia@openmailbox.org> |
|---|---|
| Date | 2017-03-06 20:50 +0100 |
| Subject | Re: [SOLVED] Re: Security hole in LXDE? |
| Message-ID | <ti6NS-4s3-77@gated-at.bofh.it> |
| In reply to | #178501 |
Greg Wooledge: > On Mon, Mar 06, 2017 at 06:31:46PM +0000, Joe wrote: >> Debian appears to use the group 'sudo' as an administrative group, >> where some other distributions use 'wheel'. >> >> I would not have thought that users would be added to it by default, >> there are no members on my sid/xfce4 workstation. Indeed, up to Jessie, >> sudo was not installed at all by default, and may still not be. > > If you use the regular Debian installer, the user account that you > create during installation gets added to a lot of these special groups > (sudo, cdrom, floppy, audio, video, ...?). Users that you create > post-installtion using adduser or useradd do not. On an Debian-lxde installer you are asked for a root pass and then a username/pass As I remember before you manually add a user in the user group the sudo command results to error. Before I figured it out I had to use su instead and any admin-package required user:root and pass to run. After adding a user in the sudo list all such packages ask for the user's pass. I think it is a sensible policy. -- "The most violent element in society is ignorance" rEG
[toc] | [prev] | [next] | [standalone]
| From | Davor Balder <davor@cropakglobal.com> |
|---|---|
| Date | 2017-02-27 11:10 +0100 |
| Message-ID | <tfqpI-45z-17@gated-at.bofh.it> |
| In reply to | #178187 |
Hi Hans, Question 1 which one: stable, testing or unstable? Generally (to aid in your investigation): 1.) It may be a good idea just to recheck your sudo settings first (/etc/sudoers). (relevant uncommented setting on this system: ## ## User privilege specification ## root ALL=(ALL) ALL 2.) The other thing would be to check your regular user's group settings (group memberships). For example (on this system): [davor@lucifer ~]$ groups davor wheel plugdev users Other than that, ensure you are not running as root (or sudo), ensure you are updated, reboot and try again as regular user. LXDE is very mature, this is unlikely to happen. Cheers D On 27/02/17 20:19, Hans wrote: > Hi folks, > > on my system /debian-amd64/testing) I can start Synaptic as a normal user, > just by using the user password. In KDE this is not possible, there I need the > root password. > > I do not have sudo in use. > > As I do not know, if this is a problem on my system (I have no second one to > confirm this)., maybe please someone else could check this. > > If I am correct, this is a security hole. If I am wrong, I have to recheck my > system. > > Thank you for your help. > > Best > > Hans >
[toc] | [prev] | [next] | [standalone]
| From | Hans <hans.ullrich@loop.de> |
|---|---|
| Date | 2017-02-27 11:30 +0100 |
| Message-ID | <tfqJ4-4cn-17@gated-at.bofh.it> |
| In reply to | #178190 |
Am Montag, 27. Februar 2017, 21:00:15 CET schrieb Davor Balder: > Hi Hans, > > Question 1 which one: stable, testing or unstable? testing/amd64 > > Generally (to aid in your investigation): > I did, but found nothing unusual. If no one can confirm this, it is a problem on my system! Hans
[toc] | [prev] | [next] | [standalone]
| From | GiaThnYgeia <GiaThnYgeia@openmailbox.org> |
|---|---|
| Date | 2017-02-27 12:20 +0100 |
| Message-ID | <tfrvs-4MR-3@gated-at.bofh.it> |
| In reply to | #178193 |
testingAmd64LXDE I have never, not once, been able to run synaptic in any similar system without a root or a sudo password. Not to execute a command, just to get the gui up you need a password. I don't know whether creating a user with 100% admin privileges will still require a pass or not, I suspect it would still. As if you add a user in the sudo group it is the user's pass that is asked. So something is wrong on your specific installation. Hans: > Am Montag, 27. Februar 2017, 21:00:15 CET schrieb Davor Balder: >> Hi Hans, >> >> Question 1 which one: stable, testing or unstable? > > testing/amd64 >> >> Generally (to aid in your investigation): >> > I did, but found nothing unusual. > > If no one can confirm this, it is a problem on my system! > > Hans > -- "The most violent element in society is ignorance" rEG
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2017-02-27 23:00 +0100 |
| Message-ID | <tfBuO-38U-7@gated-at.bofh.it> |
| In reply to | #178195 |
On Mon 27 Feb 2017 at 11:13:00 (+0000), GiaThnYgeia wrote: > testingAmd64LXDE > > I have never, not once, been able to run synaptic in any similar system > without a root or a sudo password. Not to execute a command, just to > get the gui up you need a password. Why would that be? You should be able to do so. There's a popup window that says this: Starting "Synaptic Package Manager" without administrative privileges You will not be able to apply any changes, but you can still export the marked changes or create a download script for them. I can select packages, look at their properties, dependencies, installed files, get changelogs etc. I can edit some of the preferences. I can see the immediate effects of that in files like ~/.synaptic/synaptic.conf when I click OK. I can select packages for installation and it will write a little script for me: #!/bin/sh wget -c http://ftp.us.debian.org/debian/pool/non-free/i/ibm-3270/3270-common_3.3.14ga11-1_i386.deb So it suggests that the OP has set something in their system to cause the behaviour they observe, both the popup and the fact that a user's password is sufficient for installing software. I can run (the similar program) aptitude likewise. The main differences with synaptic are that aptitude is in the user's normal PATH (whereas synaptic is in /usr/sbin); when you try to install, it asks you to consider becoming root from the Actions menu; and if you persist, it gives you the option to become root in a dialog box, and you can then type the root password. > I don't know whether creating a user with 100% admin privileges will > still require a pass or not, I suspect it would still. As if you add a > user in the sudo group it is the user's pass that is asked. So > something is wrong on your specific installation. > > Hans: > > Am Montag, 27. Februar 2017, 21:00:15 CET schrieb Davor Balder: > >> Hi Hans, > >> > >> Question 1 which one: stable, testing or unstable? > > > > testing/amd64 > >> > >> Generally (to aid in your investigation): > >> > > I did, but found nothing unusual. > > > > If no one can confirm this, it is a problem on my system! Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Hans <hans.ullrich@loop.de> |
|---|---|
| Date | 2017-02-28 11:10 +0100 |
| Message-ID | <tfMTg-2Zb-15@gated-at.bofh.it> |
| In reply to | #178236 |
I am not sure, if I some day allowed the normal user to start synaptic as a normal user. Sometimes this option is offered at the first start. If I have done this (which I was at that moment wiling to do), where do I have to look, to make this thing back to normal? Please note, that I am not using sudoers, but I am sure, I am using either kdesu or gksudo. As I am a mostly using KDE, I bet, kdesu is the one, where I might have to look for as IMO this one is the thing, that might be responsible for the rights. But where do I have to look then? Thanks for any hints. Best Hans
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2017-02-28 18:50 +0100 |
| Message-ID | <tfU4q-7JC-19@gated-at.bofh.it> |
| In reply to | #178252 |
On Tue 28 Feb 2017 at 11:02:14 (+0100), Hans wrote: > I am not sure, if I some day allowed the normal user to start synaptic as a > normal user. Sometimes this option is offered at the first start. I wouldn't know how to _prevent_ and ordinary user from running synaptic by typing /usr/sbin/synaptic, unless you had them running in some sort of restricted shall. Synaptic is obviously designed to be run by unprivileged users which is why it has that dialog box warning. > If I have done this (which I was at that moment wiling to do), where do I have > to look, to make this thing back to normal? > > Please note, that I am not using sudoers, but I am sure, I am using either > kdesu or gksudo. As I am a mostly using KDE, I bet, kdesu is the one, where I > might have to look for as IMO this one is the thing, that might be responsible > for the rights. But where do I have to look then? Yes, I agree that the clue is in your DE. I'm a WM person (fvwm) and use sudoers for allowing me to do a few things like kicking exim and changing timezones. Joe and Pontus may be more help in at least having the configuration files to look at. My assumption would be to look at the DE's configuration in /etc as you wouldn't expect a user to be able to confer this privilege on themselves. Are you user 1000? Did you gain privileges merely through being the first user at installation time? Could that be normal? Not for Pontus it seems. Just as, by default, you can gain privileges by being the person seated at the computer, so it might make some sort of sense for the first user to have certain privileges granted to them for administrating the DE. After all, you wouldn't want to run X as root, let alone a whole DE. My own working practice is a root shell inside an xterm (and my tools aren't gui), but that doesn't fit with how a DE runs things. I assume your problem lies in a helper, which picks up privileges, somewhere between the icon (or menu choice) and the synaptic binary itself. How it might have got changed, I don't know. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | GiaThnYgeia <GiaThnYgeia@openmailbox.org> |
|---|---|
| Date | 2017-02-28 13:40 +0100 |
| Message-ID | <tfPer-4pW-31@gated-at.bofh.it> |
| In reply to | #178236 |
As a user and as I understand it you should not be able to make system-wide changes and many packages affect other parts of the system. A user can install and run any package that does not affect the system, as a stand alone. The system is a whole must be maintained by the sysadmin for all users. That is my simplistic understanding. Unless it is specifically configured otherwise I don't see why these assumptions would be wrong. Imagine if I like MATE and the other user likes X11 and I delete x11 and install MATE, or I install a package that has dependency conflicts and replaces what is essential for the other users' packages. Live systems allow you to install whatever you like as they assume you are the root or sysadmin. At least that is how I understand security policy for this system. David Wright: > On Mon 27 Feb 2017 at 11:13:00 (+0000), GiaThnYgeia wrote: >> testingAmd64LXDE >> >> I have never, not once, been able to run synaptic in any similar system >> without a root or a sudo password. Not to execute a command, just to >> get the gui up you need a password. > > Why would that be? You should be able to do so. There's a popup > window that says this: > > Starting "Synaptic Package Manager" without administrative privileges > > You will not be able to apply any changes, but you can still export > the marked changes or create a download script for them. > > I can select packages, look at their properties, dependencies, > installed files, get changelogs etc. I can edit some of the > preferences. I can see the immediate effects of that in files > like ~/.synaptic/synaptic.conf when I click OK. I can select > packages for installation and it will write a little script > for me: > > #!/bin/sh > wget -c > http://ftp.us.debian.org/debian/pool/non-free/i/ibm-3270/3270-common_3.3.14ga11-1_i386.deb > > So it suggests that the OP has set something in their system > to cause the behaviour they observe, both the popup and the > fact that a user's password is sufficient for installing software. > > I can run (the similar program) aptitude likewise. The main differences > with synaptic are that aptitude is in the user's normal PATH (whereas > synaptic is in /usr/sbin); when you try to install, it asks you to > consider becoming root from the Actions menu; and if you persist, it > gives you the option to become root in a dialog box, and you can then > type the root password. > >> I don't know whether creating a user with 100% admin privileges will >> still require a pass or not, I suspect it would still. As if you add a >> user in the sudo group it is the user's pass that is asked. So >> something is wrong on your specific installation. >> >> Hans: >>> Am Montag, 27. Februar 2017, 21:00:15 CET schrieb Davor Balder: >>>> Hi Hans, >>>> >>>> Question 1 which one: stable, testing or unstable? >>> >>> testing/amd64 >>>> >>>> Generally (to aid in your investigation): >>>> >>> I did, but found nothing unusual. >>> >>> If no one can confirm this, it is a problem on my system! > > Cheers, > David. > -- "The most violent element in society is ignorance" rEG
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2017-02-28 18:50 +0100 |
| Message-ID | <tfU4q-7JC-15@gated-at.bofh.it> |
| In reply to | #178259 |
On Tue 28 Feb 2017 at 12:31:00 (+0000), GiaThnYgeia wrote: > As a user and as I understand it you should not be able to make > system-wide changes and many packages affect other parts of the system. > A user can install and run any package that does not affect the system, > as a stand alone. The system is a whole must be maintained by the > sysadmin for all users. That is my simplistic understanding. > Unless it is specifically configured otherwise I don't see why these > assumptions would be wrong. Imagine if I like MATE and the other user > likes X11 and I delete x11 and install MATE, or I install a package that > has dependency conflicts and replaces what is essential for the other > users' packages. > > Live systems allow you to install whatever you like as they assume you > are the root or sysadmin. > > At least that is how I understand security policy for this system. Apart from not understanding what you mean by "installing packages as a stand alone", that all looks fine. My post merely demonstrated that synaptic is not unusual in being runnable by ordinary users. So your inability, and the need for a password, lies outside synaptic and in the realm of the DE, which set up the icon or menu that you use to the exclusion of other methods. In a sense my post was just a gloss on Jonathan Dowland's post. So why did I comment on _your_ post? Only days ago, I mentioned someone's old d-u assertions that you couldn't run aptitude as an ordinary user, which is not true. I didn't want your statement to give people the same false impression anout synaptic, especially as that someone uses synaptic. Both aptitude and synaptic can run by an ordinary user, and it's a very safe way to run them when you don't yet fully understand their abilities. > David Wright: > > On Mon 27 Feb 2017 at 11:13:00 (+0000), GiaThnYgeia wrote: > >> testingAmd64LXDE > >> > >> I have never, not once, been able to run synaptic in any similar system > >> without a root or a sudo password. Not to execute a command, just to > >> get the gui up you need a password. > > > > Why would that be? You should be able to do so. There's a popup > > window that says this: > > > > Starting "Synaptic Package Manager" without administrative privileges > > > > You will not be able to apply any changes, but you can still export > > the marked changes or create a download script for them. > > > > I can select packages, look at their properties, dependencies, > > installed files, get changelogs etc. I can edit some of the > > preferences. I can see the immediate effects of that in files > > like ~/.synaptic/synaptic.conf when I click OK. I can select > > packages for installation and it will write a little script > > for me: > > > > #!/bin/sh > > wget -c > > http://ftp.us.debian.org/debian/pool/non-free/i/ibm-3270/3270-common_3.3.14ga11-1_i386.deb > > > > So it suggests that the OP has set something in their system > > to cause the behaviour they observe, both the popup and the > > fact that a user's password is sufficient for installing software. > > > > I can run (the similar program) aptitude likewise. The main differences > > with synaptic are that aptitude is in the user's normal PATH (whereas > > synaptic is in /usr/sbin); when you try to install, it asks you to > > consider becoming root from the Actions menu; and if you persist, it > > gives you the option to become root in a dialog box, and you can then > > type the root password. > > > >> I don't know whether creating a user with 100% admin privileges will > >> still require a pass or not, I suspect it would still. As if you add a > >> user in the sudo group it is the user's pass that is asked. So > >> something is wrong on your specific installation. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Lisi Reisz <lisi.reisz@gmail.com> |
|---|---|
| Date | 2017-03-01 01:00 +0100 |
| Message-ID | <tfZQu-2Vc-21@gated-at.bofh.it> |
| In reply to | #178281 |
On Tuesday 28 February 2017 17:45:57 David Wright wrote: > Both aptitude and synaptic can run by an ordinary user, and it's a > very safe way to run them when you don't yet fully understand their > abilities. To extend for the sake of pedantic ultra-clarity, and not to contradict: aptitude can be run as an ordinary user, but you cannot change anything as an ordinary user - only look at what is there. To change anything, e.g. install or uninstall something, you must have root privileges. Lisi
[toc] | [prev] | [next] | [standalone]
| From | cbannister@slingshot.co.nz |
|---|---|
| Date | 2017-03-25 07:20 +0100 |
| Message-ID | <toNdn-5gr-1@gated-at.bofh.it> |
| In reply to | #178190 |
On Mon, Feb 27, 2017 at 09:00:15PM +1100, Davor Balder wrote: > Hi Hans, > > Question 1 which one: stable, testing or unstable? IMHO if it's not stated then stable is to be assumed. Users who run testing/sid are generally expected to have some degree of troubleshooting knowledge (the clue is in the name.) Unfortunately, it appears that bad advice is given to run testing or sid just because a user wants a later version of a piece of software. So sure, if a user is running testing/sid then you'd expect that it would be stated early on in the post and that the user has a reasonable amount of troubleshooting knowledge, and has therefore experienced a 'special' case that someone else may have a clue about. So in a nutshell, only experienced users should be running testing/sid and therefore any posts where the dist isn't mentioned should be assumed that the user is running stable. -- The media's the most powerful entity on earth. They have the power to make the innocent guilty and to make the guilty innocent, and that's power. -- Malcolm X
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2017-02-27 12:10 +0100 |
| Message-ID | <tfrlM-4I3-11@gated-at.bofh.it> |
| In reply to | #178187 |
On Mon, 27 Feb 2017 10:19:47 +0100 Hans <hans.ullrich@loop.de> wrote: > Hi folks, > > on my system /debian-amd64/testing) I can start Synaptic as a normal > user, just by using the user password. In KDE this is not possible, > there I need the root password. > > I do not have sudo in use. > > As I do not know, if this is a problem on my system (I have no second > one to confirm this)., maybe please someone else could check this. > > If I am correct, this is a security hole. If I am wrong, I have to > recheck my system. > > Check how synaptic is being started by the menu entry. Typically, synaptic will be started by /usr/bin/synaptic-pkexec, which uses policykit to authorise an effective su for a normal user. The executable synaptic is in /usr/sbin, so will probably not work from a menu. I've changed the launcher to gksudo synaptic, which gives me explicit fine control with sudoers. I suspect what you're seeing is as intended. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Hans <hans.ullrich@loop.de> |
|---|---|
| Date | 2017-02-27 12:30 +0100 |
| Message-ID | <tfrF7-4Ql-25@gated-at.bofh.it> |
| In reply to | #178194 |
> Check how synaptic is being started by the menu entry. Typically, > synaptic will be started by /usr/bin/synaptic-pkexec, which uses > policykit to authorise an effective su for a normal user. The executable > synaptic is in /usr/sbin, so will probably not work from a menu. Yes, it is as you said. There is /usr/bin/synaptic-pkexec and /usr/sbin/synatic > > I've changed the launcher to gksudo synaptic, which gives me explicit > fine control with sudoers. > As I said: I do NOT use sudoers, and there is no entry or the user /etc/ sudoers. > I suspect what you're seeing is as intended. If so, then why not working so in KDE? And if this is intended, then this is a bug and a security hole, which should be fixed. Hans
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2017-02-27 12:50 +0100 |
| Message-ID | <tfrYu-4Xq-3@gated-at.bofh.it> |
| In reply to | #178196 |
On Mon, 27 Feb 2017 12:20:50 +0100 Hans <hans.ullrich@loop.de> wrote: > > Check how synaptic is being started by the menu entry. Typically, > > synaptic will be started by /usr/bin/synaptic-pkexec, which uses > > policykit to authorise an effective su for a normal user. The > > executable synaptic is in /usr/sbin, so will probably not work from > > a menu. > > Yes, it is as you said. There is /usr/bin/synaptic-pkexec > and /usr/sbin/synatic > > > > > I've changed the launcher to gksudo synaptic, which gives me > > explicit fine control with sudoers. > > > > As I said: I do NOT use sudoers, and there is no entry or the > user /etc/ sudoers. > > > I suspect what you're seeing is as intended. > > If so, then why not working so in KDE? And if this is intended, then > this is a bug and a security hole, which should be fixed. > I use neither LXDE nor KDE, so I would be guessing, but generally menu operation is a function of the desktop environment, and the KDE menu call may not be using pkexec. Or it may be using pkexec, but with a different policy in action. I have the common problem of using an old installation, with no recollection of the changes I have made over years to the default settings. For as long as I can remember, I have intended to log every change I make, and one day perhaps I will begin... -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Pontus Goffe <goffe.pontus@gmail.com> |
|---|---|
| Date | 2017-02-27 15:50 +0100 |
| Message-ID | <tfuMH-6Wf-31@gated-at.bofh.it> |
| In reply to | #178196 |
Den 2017-02-27 kl. 12:20, skrev Hans: > If so, then why not working so in KDE? And if this is intended, then this is a > bug and a security hole, which should be fixed. > > Hans > A fresh vanilla install of testing with LXDE installs both sudo and gksu. Without configuring any, starting synaptic from menu prompts for the root password. //PG
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | linux.debian.user
csiph-web