Re: Installing without root privileges in /usr/local

enclair <[email protected]> Thu, 8 Mar 2012 03:01:21 +0100
Newsgroups gmane.comp.gnu.stow.general
Message-ID <CAMp2XEUWUu6uregc-F2vyh3KLpW=f0irbjZSNnzVY0sGMccetg@mail.gmail.com>
--f46d0444ee0b09eea404bab1a73c
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Le 6 mars 2012 23:49, Adam Spiers <[email protected]> a =E9crit :

> That should work fine, as per
>
>
> http://www.gnu.org/software/stow/manual/html_node/Compile_002dtime-vs-Ins=
tall_002dtime.html#Compile_002dtime-vs-Install_002dtime
>

I don't understand this part.


> although you should be aware that this potentially reduces the
> security of the whole system to that of the user with access to
> /usr/local/stow.  If that user's account was compromised, and there
> was an existing symlink from /usr/local/bin/foo to
> /usr/local/stow/package/bin/foo, then the intruder would only need to
> replace the latter with a trojaned version and wait for it to be run
> in order to gain root access.
>

You mean "and wait for it to be run as root user" don't you?
For a system with only one user, the security should be the same than
installing in $HOME/local, shouldn't it?

--f46d0444ee0b09eea404bab1a73c
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Le 6 mars 2012 23:49, Adam Spiers <span dir=3D"ltr">&lt;<a href=3D"mailto:s=
[email protected]" target=3D"_blank">[email protected]</a>&gt;</span> a =
=E9crit :<br><div class=3D"im"><blockquote class=3D"gmail_quote" style=3D"m=
argin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">

That should work fine, as per<br>
<br>
 =A0<a href=3D"http://www.gnu.org/software/stow/manual/html_node/Compile_00=
2dtime-vs-Install_002dtime.html#Compile_002dtime-vs-Install_002dtime" targe=
t=3D"_blank">http://www.gnu.org/software/stow/manual/html_node/Compile_002d=
time-vs-Install_002dtime.html#Compile_002dtime-vs-Install_002dtime</a><br>

</blockquote></div><div><br>I don&#39;t understand this part.<br>=A0<br></d=
iv><div class=3D"im"><blockquote class=3D"gmail_quote" style=3D"margin:0pt =
0pt 0pt 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
although you should be aware that this potentially reduces the<br>
security of the whole system to that of the user with access to<br>
/usr/local/stow. =A0If that user&#39;s account was compromised, and there<b=
r>
was an existing symlink from /usr/local/bin/foo to<br>
/usr/local/stow/package/bin/foo, then the intruder would only need to<br>
replace the latter with a trojaned version and wait for it to be run<br>
in order to gain root access.<br></blockquote></div><br>You mean &quot;and =
wait for it to be run as root user&quot; don&#39;t you?<br>For a system wit=
h only one user, the security should be the same than installing in $HOME/l=
ocal, shouldn&#39;t it?<br>
<br>

--f46d0444ee0b09eea404bab1a73c--