Re: [Security-Discuss] msec

Antonio <[email protected]> Wed, 26 Apr 2006 19:37:08 +0200
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Alle 17:32, mercoledì 26 aprile 2006, Michael Scherer ha scritto:
> Well, first, people commented on the bug, so while no one confirmed it, i
> think this one is valid.
Thank you very much for reply. Finally I am landed on the earth :)

> But the main problem is that no one have been allocated to work on msec at
> Mandriva.
I see it, and I hope sooner or later someone at mandriva will take care of it.

> As you pointed out, i think 21243 is a duplicate of the bug 19541.
I Agree with you, but you see, also 19541 is at unconfirmed status :(
Also, it may be possible that others bugs related to msec is still assigned to 
flepied.

> And as i am gonna add on bug 19541, adding 551 instead of 550 is defeating
> the purpose of the change, as someone could simply use bruteforce attack to
> guess the content of /proc/ .
You are surely a lot more security skilled than me, mine was of course a 
temporary (and now I see unsafe) workaround

> Moreever, you should then add yourself to adm group if running msec 4.
Ok I'll do it, but now I have some questions.
First of all, please consider that I am only a student and on my machine there 
aren't of course top-secret documents :) , however I am especially interested 
to security since it is my craze (hope a day I could work as a sysadmin).
I have the habit to use 2 user account: one for web activities and the other 
for application using (for example: writing my thesis) and system 
maintenance. That is the way I (think) keep my apps less exposed to the risks 
coming from the web.
Now I'll have to add both my user account to adm group, especially the web 
account (or net_applet will not work properly).
I think adm is an abbreviation for administrators, and the first question I 
have is: don't you think giving a web user account adm rights is a security 
risk? In other words simply I don't know for what adm group is used for, 
according to the linux best practices. Could you point me to some docs 
related to group using in linux?
Or maybe msec 4 was thinked only for machine running servers, without desktop 
environment like kde?
Whatever is the case, I think apps should never be breaked silently, people 
should be advised.
Thanks again.
Antonio.
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________