Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #184907 > unrolled thread

Why debian put ~/bin beginning of $PATH

Started byspp mg <sm.sppmg@gmail.com>
First post2017-08-08 21:20 +0200
Last post2017-08-14 15:30 +0200
Articles 13 — 10 participants

Back to article view | Back to linux.debian.user


Contents

  Why debian put ~/bin beginning of $PATH spp mg <sm.sppmg@gmail.com> - 2017-08-08 21:20 +0200
    Re: Why debian put ~/bin beginning of $PATH Nicolas George <george@nsup.org> - 2017-08-08 21:40 +0200
    Re: Why debian put ~/bin beginning of $PATH John Elliot V <jj5@jj5.net> - 2017-08-08 21:40 +0200
    Re: Why debian put ~/bin beginning of $PATH Michael Lange <klappnase@freenet.de> - 2017-08-08 22:10 +0200
      Re: Why debian put ~/bin beginning of $PATH spp mg <sm.sppmg@gmail.com> - 2017-08-08 23:00 +0200
        Re: Why debian put ~/bin beginning of $PATH Michael Lange <klappnase@freenet.de> - 2017-08-08 23:30 +0200
        Re: Why debian put ~/bin beginning of $PATH Teemu Likonen <tlikonen@iki.fi> - 2017-08-09 06:50 +0200
          Re: Why debian put ~/bin beginning of $PATH Teemu Likonen <tlikonen@iki.fi> - 2017-08-09 07:00 +0200
        Re: Why debian put ~/bin beginning of $PATH "Gian Uberto Lauri" <saint@eng.it> - 2017-08-09 18:20 +0200
          Re: Why debian put ~/bin beginning of $PATH David Wright <deblis@lionunicorn.co.uk> - 2017-08-09 19:00 +0200
      Re: Why debian put ~/bin beginning of $PATH Greg Wooledge <wooledg@eeg.ccf.org> - 2017-08-09 15:20 +0200
    Re: Why debian put ~/bin beginning of $PATH soyeomul@doraji.xyz (Byung-Hee HWANG (황병희, 黃炳熙)) - 2017-08-11 16:00 +0200
    Re: Why debian put ~/bin beginning of $PATH Vincent Lefevre <vincent@vinc17.net> - 2017-08-14 15:30 +0200

#184907 — Why debian put ~/bin beginning of $PATH

Fromspp mg <sm.sppmg@gmail.com>
Date2017-08-08 21:20 +0200
SubjectWhy debian put ~/bin beginning of $PATH
Message-ID<ucicO-4h6-17@gated-at.bofh.it>
Hi all

In the ~/.profile has below default setting:

--------------
# set PATH so it includes user's private bin if it exists
if [ -d "$HOME/bin" ] ; then
    PATH="$HOME/bin:$PATH"
fi
--------------

Why put ~/bin beginning ? Is that dangerous ?

Thanks .

[toc] | [next] | [standalone]


#184909

FromNicolas George <george@nsup.org>
Date2017-08-08 21:40 +0200
Message-ID<uciwa-4sa-9@gated-at.bofh.it>
In reply to#184907
Le duodi 22 thermidor, an CCXXV, spp mg a écrit :
> Why put ~/bin beginning ? Is that dangerous ?

No.

-- 
  Nicolas George

[toc] | [prev] | [next] | [standalone]


#184910

FromJohn Elliot V <jj5@jj5.net>
Date2017-08-08 21:40 +0200
Message-ID<uciwa-4sa-13@gated-at.bofh.it>
In reply to#184907

[Multipart message — attachments visible in raw view] — view raw

On 09/08/17 05:11, spp mg wrote:
> In the ~/.profile has below default setting:
> 
> --------------
> # set PATH so it includes user's private bin if it exists
> if [ -d "$HOME/bin" ] ; then
>     PATH="$HOME/bin:$PATH"
> fi
> --------------
> 
> Why put ~/bin beginning ?

So that your own stuff has precedence...

> Is that dangerous ?

Not really. Only you or a system administrator would have write access
to ~/bin. What makes you think it might be dangerous?

-- 
E: jj5@jj5.net
P: +61 4 3505 7839
W: https://www.jj5.net/

[toc] | [prev] | [next] | [standalone]


#184911

FromMichael Lange <klappnase@freenet.de>
Date2017-08-08 22:10 +0200
Message-ID<uciZb-5aW-1@gated-at.bofh.it>
In reply to#184907
Hi,

On Wed, 9 Aug 2017 03:11:48 +0800
spp mg <sm.sppmg@gmail.com> wrote:

> Hi all
> 
> In the ~/.profile has below default setting:
> 
> --------------
> # set PATH so it includes user's private bin if it exists
> if [ -d "$HOME/bin" ] ; then
>     PATH="$HOME/bin:$PATH"
> fi
> --------------
> 
> Why put ~/bin beginning ? Is that dangerous ?

like other people already pointed out there shouldn't be anything
dangerous about this.
One possible use case is for example that you could put there a
minimal script that temporarily overrides some environment variable, like
one I have here which reads:

#!/bin/bash
GTK_IM_MODULE=gtk /usr/bin/poedit $@
exit $?

This way I can conveniently call "poedit <filename>" with the desired
setting of GTK_IM_MODULE without either having to type the whole thing
each time or else having to permanently change GTK_IM_MODULE's setting
(the default value of which I modified for other reasons).

Best regards

Michael

.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Fascinating, a totally parochial attitude.
		-- Spock, "Metamorphosis", stardate 3219.8

[toc] | [prev] | [next] | [standalone]


#184913

Fromspp mg <sm.sppmg@gmail.com>
Date2017-08-08 23:00 +0200
Message-ID<ucjLA-5ty-21@gated-at.bofh.it>
In reply to#184911
2017-08-09 4:04 GMT+08:00 Michael Lange <klappnase@freenet.de>:
> Hi,
>
> On Wed, 9 Aug 2017 03:11:48 +0800
> spp mg <sm.sppmg@gmail.com> wrote:
>
>> Hi all
>>
>> In the ~/.profile has below default setting:
>>
>> --------------
>> # set PATH so it includes user's private bin if it exists
>> if [ -d "$HOME/bin" ] ; then
>>     PATH="$HOME/bin:$PATH"
>> fi
>> --------------
>>
>> Why put ~/bin beginning ? Is that dangerous ?
>
> like other people already pointed out there shouldn't be anything
> dangerous about this.
> One possible use case is for example that you could put there a
> minimal script that temporarily overrides some environment variable, like
> one I have here which reads:
>
> #!/bin/bash
> GTK_IM_MODULE=gtk /usr/bin/poedit $@
> exit $?
>
> This way I can conveniently call "poedit <filename>" with the desired
> setting of GTK_IM_MODULE without either having to type the whole thing
> each time or else having to permanently change GTK_IM_MODULE's setting
> (the default value of which I modified for other reasons).
>
> Best regards
>
> Michael
>
> .-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.
>
> Fascinating, a totally parochial attitude.
>                 -- Spock, "Metamorphosis", stardate 3219.8
>

Thinks to reply (very fast :D)

I think it's may dangerous because generally system command should be
highter older then user's command.

For example , some guy put a "rm" but named "ls" to ~/bin . This "ls"
can be virus or ransomware , user may not know it's not which he
want("ls").

So I think put ~/bin to tail of $PATH has better security for normal user.

For me, I will avoid use same name with exist command, and for user
who want use same name , I believe he know or will learn how to modify
$PATH.


I mean , put ~/bin in tail of $PATH will batter for default setting,
so does developer has another reason to put to beginning ?

[toc] | [prev] | [next] | [standalone]


#184914

FromMichael Lange <klappnase@freenet.de>
Date2017-08-08 23:30 +0200
Message-ID<uckeB-5SA-5@gated-at.bofh.it>
In reply to#184913
Hi,

On Wed, 9 Aug 2017 04:56:58 +0800
spp mg <sm.sppmg@gmail.com> wrote:

(...)
> For example , some guy put a "rm" but named "ls" to ~/bin . This "ls"
> can be virus or ransomware , user may not know it's not which he
> want("ls").

a user without administrator privilege can generally put "malware"
anywhere in *his own* home directory and it could possibly cause the same
damage from there (if the system is configured properly hopefully not
that much), so this does not matter, I think.

I think you forget that your "some guy" must be either the user him- or
herself or the system administrator (root)! If your users or
sysadmins desperately want to shoot themselves in the foot, don't worry,
they will find some way, you will not be able to stop them. But why would
normal people do such a thing? And any malware programmer who secretly
"injects" something bad into your system will probably not rely on ~/bin
being at the start of PATH, these people have other ways.

> 
> So I think put ~/bin to tail of $PATH has better security for normal
> user.

Why? If the user puts a program called "evilmalware" there, it simply
does not matter where in PATH it is. And when the user does something
sane instead, as in my "poedit" example, it will no longer work :(

> 
> For me, I will avoid use same name with exist command, and for user
> who want use same name , I believe he know or will learn how to modify
> $PATH.
> 
> 
> I mean , put ~/bin in tail of $PATH will batter for default setting,
> so does developer has another reason to put to beginning ?

I think the reason is exactly as I and others have said, the benefit to
security you get by omitting ~/bin from the beginning of PATH is more
"feeling" than "reality", the real dangers are waiting somewhere else :)
And the benefit of this default setting is that a user without privilege
may override a system default command. 

Best regards

Michael

.-.. .. ...- .   .-.. --- -. --.   .- -. -..   .--. .-. --- ... .--. . .-.

Where there's no emotion, there's no motive for violence.
		-- Spock, "Dagger of the Mind", stardate 2715.1

[toc] | [prev] | [next] | [standalone]


#184918

FromTeemu Likonen <tlikonen@iki.fi>
Date2017-08-09 06:50 +0200
Message-ID<ucr6p-1Vc-5@gated-at.bofh.it>
In reply to#184913

[Multipart message — attachments visible in raw view] — view raw

spp mg [2017-08-09 04:56:58+08] wrote:

> For example , some guy put a "rm" but named "ls" to ~/bin . This "ls"
> can be virus or ransomware , user may not know it's not which he
> want("ls").

The "some guy" who does that will also modify the ~/.profile file or
similar startup scripts to _ensure_ that their program is in the
beginning of the PATH, no matter what the PATH variable was originally.

If $USER has a malicious program running with their $UID the program can
do everything the $USER can do. It's a game over situation and default
settings in ~/.profile or similar do not matter.

But sometimes it may be useful to write a root-owner startup script (one
example: /etc/X11/Xsession.d/50custom-stuff) which could do something
like

    rm --force "$HOME/bin"
    cp --recursive --force /etc/skel/. "$HOME"

so that some default files are restored at every login.

-- 
/// Teemu Likonen   - .-..   <https://keybase.io/tlikonen> //
// PGP: 4E10 55DC 84E9 DFF6 13D7 8557 719D 69D3 2453 9450 ///

[toc] | [prev] | [next] | [standalone]


#184919

FromTeemu Likonen <tlikonen@iki.fi>
Date2017-08-09 07:00 +0200
Message-ID<ucrg6-1Yt-11@gated-at.bofh.it>
In reply to#184918

[Multipart message — attachments visible in raw view] — view raw

Teemu Likonen [2017-08-09 07:42:43+03] wrote:

>     rm --force "$HOME/bin"

Fix:

    rm --force --recursive "$HOME/bin"

-- 
/// Teemu Likonen   - .-..   <https://keybase.io/tlikonen> //
// PGP: 4E10 55DC 84E9 DFF6 13D7 8557 719D 69D3 2453 9450 ///

[toc] | [prev] | [next] | [standalone]


#184941

From"Gian Uberto Lauri" <saint@eng.it>
Date2017-08-09 18:20 +0200
Message-ID<ucBS9-1ep-5@gated-at.bofh.it>
In reply to#184913
>>>>> "慕冬" == 慕 冬亮 <mudongliangabcd@hotmail.com> writes:

慕冬> User's command is usually stored in "/usr/local/bin". It should
慕冬> be placed before "/bin" in the $PATH.

/usr/local is a directory hierarchy for binaries typical of the local
installation and being, by default, owned by root, it is not a
directory for user commands.

Having ~/bin before /bin and /usr/bin (and /usr/local/bin) is of no
harm at all if your account is safe enough.

If and only if someone can log on with your account, she can put a
malicious copy/wrapper of a system command (ls to name one) in your
bin and you could trigger it thinking to use the system version.

What *is* dangerous is having . before system directories, especially
on multi-user machines.

In this scenario, user A, who has . in the path before /bin, goes in a
directory of user B and does an 'ls'.

That directory contains an executable called ls that is smart enough
to hide itself. But bastard enough to do something nasty, a Trojan
horse. And user A just brought it within the walls...

-- 
 /\           ___                                    Ubuntu: ancient
/___/\_|_|\_|__|___Gian Uberto Lauri_____               African word
  //--\| | \|  |   Integralista GNUslamico            meaning "I can
\/                 coltivatore diretto di software       not install
     già sistemista a tempo (altrui) perso...                Debian"

Warning: gnome-config-daemon considered more dangerous than GOTO

[toc] | [prev] | [next] | [standalone]


#184944

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2017-08-09 19:00 +0200
Message-ID<ucCuU-1ua-75@gated-at.bofh.it>
In reply to#184941
On Wed 09 Aug 2017 at 18:04:56 (+0200), Gian Uberto Lauri wrote:

> Having ~/bin before /bin and /usr/bin (and /usr/local/bin) is of no
> harm at all if your account is safe enough.
> 
> If and only if someone can log on with your account, she can put a
> malicious copy/wrapper of a system command (ls to name one) in your
> bin and you could trigger it thinking to use the system version.
> 
> What *is* dangerous is having . before system directories, especially
> on multi-user machines.
> 
> In this scenario, user A, who has . in the path before /bin, goes in a
> directory of user B and does an 'ls'.
> 
> That directory contains an executable called ls that is smart enough
> to hide itself. But bastard enough to do something nasty, a Trojan
> horse. And user A just brought it within the walls...

While putting . _anywhere_ in PATH would be stupid, there is a more
insidious trap for the unaware, namely mistaking : for a delimiter
instead of a separator.

An extra colon (anywhere) will yield a null entry.

A null entry in PATH is treated as the current directory.

Examples:   foo:bar:   foo::bar   :foo:bar   and obviously   :foo:bar:

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#184934

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-08-09 15:20 +0200
Message-ID<ucz3X-7wj-9@gated-at.bofh.it>
In reply to#184911
On Tue, Aug 08, 2017 at 10:04:32PM +0200, Michael Lange wrote:
> #!/bin/bash
> GTK_IM_MODULE=gtk /usr/bin/poedit $@
> exit $?

Should be:

#!/bin/bash
GTK_IM_MODULE=gtk exec /usr/bin/poedit "$@"

You could also use #!/bin/sh, since this doesn't use any bash extensions.

[toc] | [prev] | [next] | [standalone]


#185041

Fromsoyeomul@doraji.xyz (Byung-Hee HWANG (황병희, 黃炳熙))
Date2017-08-11 16:00 +0200
Message-ID<udiDL-4ef-7@gated-at.bofh.it>
In reply to#184907
> Why put ~/bin beginning ?

2 weeks ago, i installed new Ruby. At that time it was proper to me. By
the Debian rule, users can test new program. Yes i think in positive. 

Sincerely,

-- 
^고맙습니다 _布德天下_ 감사합니다_^))//

[toc] | [prev] | [next] | [standalone]


#185176

FromVincent Lefevre <vincent@vinc17.net>
Date2017-08-14 15:30 +0200
Message-ID<uenBo-4G7-19@gated-at.bofh.it>
In reply to#184907
On 2017-08-09 03:11:48 +0800, spp mg wrote:
> In the ~/.profile has below default setting:
> 
> --------------
> # set PATH so it includes user's private bin if it exists
> if [ -d "$HOME/bin" ] ; then
>     PATH="$HOME/bin:$PATH"
> fi
> --------------
> 
> Why put ~/bin beginning ? Is that dangerous ?

No, it's the opposite that is potentially dangerous. For instance,
you install some executable foo in your ~/bin, so that you can run
just "foo". Then, imagine that after some system upgrade or package
installation, a new executable "foo" gets installed somewhere in
the system path. So, when you run "foo", it will no longer be your
executable, but the system one, and if this executable is destructive,
you may lose data...

It is "." that must never be put in front of the path. Putting it
at the end might be OK, but this is not even recommended, due to
the above issue and also because you may run a wrong executable by
mistake.

-- 
Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web