phpbb and sql errors asp sqlserver odbc sql errors

Today´s Diary

If you have more information or corrections regarding our diary, click here to contact us.

Published: 2009-11-19,
Last Updated: 2009-11-20 13:43:09 UTC
by Joel Esler (Version: 2)
4 comment(s) Facebookacebook witter

A "bug" created back in November against the latest Fedora release (12) indicates that, through the GUI, desktop users of the Fedora system are able to install signed packages without root privileges or root authentication.  Yes, you just read that correctly.  (I'll give you a second re-read that sentence so I don't have to retype it.)  Yes, "it's a feature, not a bug".

In all my travels I've only ran across one company, ever, that has Fedora rolled out as an enterprise operating system on every desktop.  But what kind of security implications does this have?  I obviously don't have to explain why this is (may be) a bad idea to the readers of the ISC, as we are all security minded people.  

Now, the restrictions.  This change does not affect yum on the command line.  This only affects installing things through the GUI.  (Not that helps any, as most users will be running the GUI anyway.)  You can also disable it.

create a file in:

/var/lib/polkit-1/localauthority/20-org.d  (you can name if file anything you want)

and include the following:

[NoUsersInstallAnythingWithoutPassword]
Identity=unix-user:someone;unix-user:someone_else
Action=org.freedesktop.packagekit.*
ResultAny=auth_admin
ResultInactive=auth_admin
ResultActive=auth_admin

 

(the above came from the release notes for Fedora 12, found here.  

Also, I found this as a solution:

pklalockdown --lockdown org.freedesktop.packagekit.package-install

Currently in the bug, there is some debate about if they should revert this feature.  So, this may be just temporary.  

 

UPDATE:  After I wrote about this yesterday, an email was sent out to the Fedora Developers List saying that, essentially, have reversed the decision and will now require the root password for the installation of packages.  Read the email here.  Thanks to the commenters on this post for the update.

-- Joel Esler | http://blog.joelesler.net | http://twitter.com/joelesler

Keywords:
4 comment(s) Facebookacebook witter
PHP 5.3.1 is released. With many of the websites on the net relying on PHP and the number of attacks we see, consider upgrading. This release has over 100 bug fixes, some of which are security related.

If you have more information or corrections regarding our diary, click here to contact us.

Diary Archive

DateAuthorTitle
2009-11-19Joel Esler Fedora to allow the installation of packages, without root privileges?
2009-11-18Rob VandenBrink Using a Cisco Router as a “Remote Collector” for tcpdump or Wireshark
2009-11-17Guy Bruneau OpenVPN Fixed OpenSSL Session Renegotiation Issue
2009-11-17Guy Bruneau Metasploit Framework 3.3 Released
2009-11-16G. N. White Reports of a successful exploit of the SSL Renegotiation Vulnerability?
2009-11-14Adrien de Beaupre Microsoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released
2009-11-13Deborah Hale Pushdo/Cutwail Spambot - A Little Known BIG Problem
2009-11-13Deborah Hale It's Never Too Early To Start Teaching Them
2009-11-13Adrien de Beaupre TLS & SSLv3 renegotiation vulnerability explained
2009-11-13Adrien de Beaupre Flash Origin Policy Attack
Complete Archive
Search Diaries:

StormCast


last update 08 hrs 20 min ago.

Featured Event

Latest Reading Room Papers

Gathering Security Metrics and Reaping the Rewards
Hey Dude! I Can Do a Great Humphrey Bogart!
A Multi-Perspective View of PHP Remote File Include Attacks
Check Point Firewall Log Analysis In-Depth
Efficiently Deducing IDS False Positives Using System Profiling

Poll

I back up data on my home PCs...
daily, or whenever files change or get added
once a week
once a month
every now and then
other (please leave comment)

Trends

trends more details

World Map

Worldmap