Re: [Security-Discuss] msec
Antonio <[email protected]> Wed, 26 Apr 2006 19:37:08 +0200
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
Alle 17:32, mercoledì 26 aprile 2006, Michael Scherer ha scritto: > Well, first, people commented on the bug, so while no one confirmed it, i > think this one is valid. Thank you very much for reply. Finally I am landed on the earth :) > But the main problem is that no one have been allocated to work on msec at > Mandriva. I see it, and I hope sooner or later someone at mandriva will take care of it. > As you pointed out, i think 21243 is a duplicate of the bug 19541. I Agree with you, but you see, also 19541 is at unconfirmed status :( Also, it may be possible that others bugs related to msec is still assigned to flepied. > And as i am gonna add on bug 19541, adding 551 instead of 550 is defeating > the purpose of the change, as someone could simply use bruteforce attack to > guess the content of /proc/ . You are surely a lot more security skilled than me, mine was of course a temporary (and now I see unsafe) workaround > Moreever, you should then add yourself to adm group if running msec 4. Ok I'll do it, but now I have some questions. First of all, please consider that I am only a student and on my machine there aren't of course top-secret documents :) , however I am especially interested to security since it is my craze (hope a day I could work as a sysadmin). I have the habit to use 2 user account: one for web activities and the other for application using (for example: writing my thesis) and system maintenance. That is the way I (think) keep my apps less exposed to the risks coming from the web. Now I'll have to add both my user account to adm group, especially the web account (or net_applet will not work properly). I think adm is an abbreviation for administrators, and the first question I have is: don't you think giving a web user account adm rights is a security risk? In other words simply I don't know for what adm group is used for, according to the linux best practices. Could you point me to some docs related to group using in linux? Or maybe msec 4 was thinked only for machine running servers, without desktop environment like kde? Whatever is the case, I think apps should never be breaked silently, people should be advised. Thanks again. Antonio. ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________