![]() |
ubuntu.com - launchpad.net - ubuntu help
|
|
|||||||
Hello, Unregistered You are browsing a READ only archive of the main support categories pre 4/21/2008. You will not be able to post or reply any threads in this section.
|
|
Server Platforms Discussion regarding any server based ubuntu release. |
|
|
Thread Tools | Display Modes |
|
|
#1 |
|
Marketing Team
![]() |
About sudo and security
I was wondering about sudo and the timestamp option. By default, if you run a command that requires sudo with the timestamp, you don;t have to reinput the password. With this in mind, could I not write a script to replace one of the menu items with a script that would run the program as normal, thus prompting for a password, but also run some sort of malware?
Corey |
|
|
|
|
|
#2 |
|
Gee! These Aren't Roasted!
![]() Join Date: Nov 2004
Location: Ottawa, Canada
Beans: 130
Ubuntu 7.10 Gutsy Gibbon
|
Re: About sudo and security
Yes. Next question.
That person would need to hack archives or security.ubuntulinux.org, or be an insider. I'm sure that it would be found out fairly quickly. Or, you could tell everyone that you have some packages in a third-party repository. Once somebody finds out that there's malware, I'm sure someone will post big warnings about your site. Plus, it would be trivial to find out your ISP, etc... So in the end, I wouldn't lose sleep over it. |
|
|
|
|
|
#3 |
|
A Carafe of Ubuntu
![]() |
Re: About sudo and security
Good to see that this issue has been covered. How about the current state of this issue? Does anybody have input? I was about to make a new post, 'cause the matter just popped into my mind, good to see that this has been addressed...
Regards -B
__________________
* I'm the operator with my pocket calculator * |
|
|
|
|
|
#4 | |
|
Dark Roasted Ubuntu
![]() ![]() Join Date: Mar 2007
Location: Rochester, NY USA
Beans: 1,007
Ubuntu 9.10 Karmic Koala
|
Re: About sudo and security
Quote:
|
|
|
|
|
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|