Re: Installing without root privileges in /usr/local
enclair <[email protected]> Thu, 8 Mar 2012 03:01:21 +0100
| Newsgroups | gmane.comp.gnu.stow.general |
|---|---|
| Message-ID | <CAMp2XEUWUu6uregc-F2vyh3KLpW=f0irbjZSNnzVY0sGMccetg@mail.gmail.com> |
--f46d0444ee0b09eea404bab1a73c Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Le 6 mars 2012 23:49, Adam Spiers <[email protected]> a =E9crit : > That should work fine, as per > > > http://www.gnu.org/software/stow/manual/html_node/Compile_002dtime-vs-Ins= tall_002dtime.html#Compile_002dtime-vs-Install_002dtime > I don't understand this part. > although you should be aware that this potentially reduces the > security of the whole system to that of the user with access to > /usr/local/stow. If that user's account was compromised, and there > was an existing symlink from /usr/local/bin/foo to > /usr/local/stow/package/bin/foo, then the intruder would only need to > replace the latter with a trojaned version and wait for it to be run > in order to gain root access. > You mean "and wait for it to be run as root user" don't you? For a system with only one user, the security should be the same than installing in $HOME/local, shouldn't it? --f46d0444ee0b09eea404bab1a73c Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Le 6 mars 2012 23:49, Adam Spiers <span dir=3D"ltr"><<a href=3D"mailto:s= [email protected]" target=3D"_blank">[email protected]</a>></span> a = =E9crit :<br><div class=3D"im"><blockquote class=3D"gmail_quote" style=3D"m= argin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"> That should work fine, as per<br> <br> =A0<a href=3D"http://www.gnu.org/software/stow/manual/html_node/Compile_00= 2dtime-vs-Install_002dtime.html#Compile_002dtime-vs-Install_002dtime" targe= t=3D"_blank">http://www.gnu.org/software/stow/manual/html_node/Compile_002d= time-vs-Install_002dtime.html#Compile_002dtime-vs-Install_002dtime</a><br> </blockquote></div><div><br>I don't understand this part.<br>=A0<br></d= iv><div class=3D"im"><blockquote class=3D"gmail_quote" style=3D"margin:0pt = 0pt 0pt 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> although you should be aware that this potentially reduces the<br> security of the whole system to that of the user with access to<br> /usr/local/stow. =A0If that user's account was compromised, and there<b= r> was an existing symlink from /usr/local/bin/foo to<br> /usr/local/stow/package/bin/foo, then the intruder would only need to<br> replace the latter with a trojaned version and wait for it to be run<br> in order to gain root access.<br></blockquote></div><br>You mean "and = wait for it to be run as root user" don't you?<br>For a system wit= h only one user, the security should be the same than installing in $HOME/l= ocal, shouldn't it?<br> <br> --f46d0444ee0b09eea404bab1a73c--