Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #178348

Re: Security hole in LXDE?

From <tomas@tuxteam.de>
Newsgroups linux.debian.user
Subject Re: Security hole in LXDE?
Date 2017-03-02 21:20 +0100
Message-ID <tgFmF-7nY-7@gated-at.bofh.it> (permalink)
References <tfpMZ-3yz-1@gated-at.bofh.it> <tgxS9-29S-1@gated-at.bofh.it> <tgyOd-2Mh-1@gated-at.bofh.it> <tgz7A-2SA-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, Mar 02, 2017 at 02:32:19PM +0100, Hans wrote:

[snip snip]

OK, given your answers, the recommended path would be to remove your
user (hans) from group sudo, perhaps so:

  deluser hans sudo

(you've to be root for that, perhaps with -ahem- sudo ;-)

and then see whether the system behaves as you expect. You can change
things back with

  adduser hans sudo

(this time not with sudo, heh).

Note that sudo is pretty useful in other situations: you can specify
that users get sudo powers only for specific programs: that would e.g.
allow regular users to invoke a backup even if they aren't allowed to
read the files they back up. Careful planning is a good idea, since
if (to keep with the example) they have access to the backup medium
they would be able to read the files anyway -- or worse.

Regards
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAli4fh4ACgkQBcgs9XrR2kYN5gCaAk7PblG3qf+LoMHzldB9Mz8x
N9oAn3xgOJzWcEEugWFQsGu3ejhp6UEd
=TbB6
-----END PGP SIGNATURE-----

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 10:30 +0100
  Re: Security hole in LXDE? Jonathan Dowland <jmtd@debian.org> - 2017-02-27 11:00 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:20 +0100
      Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 16:40 +0100
      Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 11:50 +0100
        Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 12:40 +0100
          Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 13:20 +0100
            Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 14:20 +0100
              Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-02 14:40 +0100
                Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:20 +0100
              Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-03-02 15:10 +0100
                Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-02 21:40 +0100
      [SOLVED] Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-03-06 18:30 +0100
        Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 19:40 +0100
          Re: [SOLVED] Re: Security hole in LXDE? Greg Wooledge <wooledg@eeg.ccf.org> - 2017-03-06 19:50 +0100
            Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 20:00 +0100
              Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 20:40 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 21:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Curt <curty@free.fr> - 2017-03-06 21:50 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-03-06 22:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-06 22:00 +0100
                Re: [SOLVED] Re: Security hole in LXDE? <tomas@tuxteam.de> - 2017-03-07 09:10 +0100
                Re: [SOLVED] Re: Security hole in LXDE? Brian <ad44@cityscape.co.uk> - 2017-03-07 13:10 +0100
            Re: [SOLVED] Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-03-06 20:50 +0100
  Re: Security hole in LXDE? Davor Balder <davor@cropakglobal.com> - 2017-02-27 11:10 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 11:30 +0100
      Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-27 12:20 +0100
        Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-27 23:00 +0100
          Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-28 11:10 +0100
            Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
          Re: Security hole in LXDE? GiaThnYgeia <GiaThnYgeia@openmailbox.org> - 2017-02-28 13:40 +0100
            Re: Security hole in LXDE? David Wright <deblis@lionunicorn.co.uk> - 2017-02-28 18:50 +0100
              Re: Security hole in LXDE? Lisi Reisz <lisi.reisz@gmail.com> - 2017-03-01 01:00 +0100
    Re: Security hole in LXDE? cbannister@slingshot.co.nz - 2017-03-25 07:20 +0100
  Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:10 +0100
    Re: Security hole in LXDE? Hans <hans.ullrich@loop.de> - 2017-02-27 12:30 +0100
      Re: Security hole in LXDE? Joe <joe@jretrading.com> - 2017-02-27 12:50 +0100
      Re: Security hole in LXDE? Pontus Goffe <goffe.pontus@gmail.com> - 2017-02-27 15:50 +0100

csiph-web