Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.devel > #100998

Re: Debian package manager privilege escalation attack

From Philipp Kern <pkern@debian.org>
Newsgroups linux.debian.devel
Subject Re: Debian package manager privilege escalation attack
Date 2021-08-12 20:10 +0200
Message-ID <CLnjr-3va-1@gated-at.bofh.it> (permalink)
References (3 earlier) <CLcem-4Xu-9@gated-at.bofh.it> <CLco1-50t-1@gated-at.bofh.it> <CLg8h-7qo-3@gated-at.bofh.it> <CLhnH-87Q-1@gated-at.bofh.it> <CLlhD-26h-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 2021-08-12 17:56, Marc Haber wrote:
> On Thu, 12 Aug 2021 13:44:24 +0200, Philipp Kern <pkern@debian.org>
> wrote:
>> On 2021-08-12 12:23, Polyna-Maude Racicot-Summerside wrote:
>>> Now if people start doing stuff they don't master than it's not
>>> privilege escalation but much more something like another 
>>> manifestation
>>> of human stupidity. And this, there won't be a number of article
>>> sufficient to make people change.
>> [...]
>>> This is only a article made to get people onto a website and see
>>> publicity or whatever goal the author set. There's nothing genuine in
>>> there.
>> 
>> I think it's less about human stupidity than about all the knowledge 
>> you
>> need to acquire (and retain) to securely administer a system. It is 
>> not
>> easy. The concern expressed here is pretty much common knowledge among
>> sysadmins of ye olde times.
> 
> I think the essence of the article is, that on some apt/dpkg using
> distributions, a "normal" user gets sudo rights to do apt only (I have
> never seen that on Debian, do we do this in some corner case?) and is
> able to escalate to root from that trivially, even without doctoring
> some malicious package, just shell out from dpkg's conffile prompt to
> a full root shell.

You know that this is a bad idea (granting sudo to apt without a 
wrapper). I know that this is a bad idea. That was my point. Plus that 
this is a very common trope in multi-user settings that you want to hand 
out some privilege to install packages.

Kind regards
Philipp Kern

Back to linux.debian.devel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Debian package manager privilege escalation attack Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2021-08-12 05:40 +0200
  Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 06:00 +0200
    Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 07:50 +0200
      Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:20 +0200
        Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:30 +0200
          Re: Debian package manager privilege escalation attack Paul Tagliamonte <paultag@debian.org> - 2021-08-12 15:00 +0200
  Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 07:40 +0200
    Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 08:40 +0200
      Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:40 +0200
        Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 09:00 +0200
      Re: Debian package manager privilege escalation attack Ansgar <ansgar@43-1.org> - 2021-08-12 10:40 +0200
        Re: Debian package manager privilege escalation attack Vincent Bernat <bernat@debian.org> - 2021-08-12 11:20 +0200
      Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 11:20 +0200
      Re: Debian package manager privilege escalation attack David Kalnischkies <david@kalnischkies.de> - 2021-08-12 13:50 +0200
      Re: Debian package manager privilege escalation attack Kyle Edwards <kyle.edwards@kitware.com> - 2021-08-12 14:40 +0200
        Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 14:50 +0200
  Re: Debian package manager privilege escalation attack Niels Thykier <niels@thykier.net> - 2021-08-12 07:40 +0200
    Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:20 +0200
      Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:30 +0200
        Re: Debian package manager privilege escalation attack Andrey Rahmatullin <wrar@debian.org> - 2021-08-12 08:40 +0200
        Re: Debian package manager privilege escalation attack Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-08-12 12:30 +0200
          Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 13:50 +0200
            Re: Debian package manager privilege escalation attack Marc Haber <mh+debian-devel@zugschlus.de> - 2021-08-12 18:00 +0200
              Re: Debian package manager privilege escalation attack Philipp Kern <pkern@debian.org> - 2021-08-12 20:10 +0200
                Re: Debian package manager privilege escalation attack Russ Allbery <rra@debian.org> - 2021-08-12 21:10 +0200
    Re: Debian package manager privilege escalation attack Brian Thompson <brian@hashvault.io> - 2021-08-12 08:20 +0200
      Re: Debian package manager privilege escalation attack Holger Levsen <holger@layer-acht.org> - 2021-08-12 15:20 +0200
        Re: Debian package manager privilege escalation attack Holger Levsen <holger@layer-acht.org> - 2021-08-12 18:10 +0200
        Re: Debian package manager privilege escalation attack Wouter Verhelst <wouter@debian.org> - 2021-08-16 16:50 +0200

csiph-web