Ubuntu Forums ubuntu.com - launchpad.net - ubuntu help  

Go Back   Ubuntu Forums > The Ubuntu Forum Community > Forum Archive > Main Support Categories > Server Platforms
Register Reset Password Forum Help Forum Council Search Today's Posts Mark Forums Read

Hello, Unregistered You are browsing a READ only archive of the main support categories pre 4/21/2008. You will not be able to post or reply any threads in this section.

Server Platforms
Discussion regarding any server based ubuntu release.

 
Thread Tools Display Modes
Old November 5th, 2004   #1
Burgundavia
Marketing Team
 
Join Date: Oct 2004
Location: Canada
Beans: 209
Send a message via MSN to Burgundavia
About sudo and security

I was wondering about sudo and the timestamp option. By default, if you run a command that requires sudo with the timestamp, you don;t have to reinput the password. With this in mind, could I not write a script to replace one of the menu items with a script that would run the program as normal, thus prompting for a password, but also run some sort of malware?

Corey
Burgundavia is offline   Reply With Quote
Old November 11th, 2004   #2
mr_ed
Gee! These Aren't Roasted!
 
Join Date: Nov 2004
Location: Ottawa, Canada
Beans: 130
Ubuntu 7.10 Gutsy Gibbon
Re: About sudo and security

Yes. Next question.

That person would need to hack archives or security.ubuntulinux.org, or be an insider.
I'm sure that it would be found out fairly quickly.

Or, you could tell everyone that you have some packages in a third-party repository.
Once somebody finds out that there's malware, I'm sure someone will post big warnings about your site. Plus, it would be trivial to find out your ISP, etc...

So in the end, I wouldn't lose sleep over it.
mr_ed is offline   Reply With Quote
Old January 20th, 2008   #3
bomanizer
A Carafe of Ubuntu
 
bomanizer's Avatar
 
Join Date: Jul 2005
Location: Finland
Beans: 107
Send a message via MSN to bomanizer
Re: About sudo and security

Good to see that this issue has been covered. How about the current state of this issue? Does anybody have input? I was about to make a new post, 'cause the matter just popped into my mind, good to see that this has been addressed...

Regards

-B
__________________
* I'm the operator with my pocket calculator *
bomanizer is offline   Reply With Quote
Old January 20th, 2008   #4
cprofitt
Dark Roasted Ubuntu
 
cprofitt's Avatar
 
Join Date: Mar 2007
Location: Rochester, NY USA
Beans: 1,007
Ubuntu 9.10 Karmic Koala
Re: About sudo and security

Quote:
Originally Posted by Burgundavia View Post
I was wondering about sudo and the timestamp option. By default, if you run a command that requires sudo with the timestamp, you don;t have to reinput the password. With this in mind, could I not write a script to replace one of the menu items with a script that would run the program as normal, thus prompting for a password, but also run some sort of malware?

Corey
I think it would make more sense for a 'cracker' to exploit a know buffer overflow and take root control that way.
cprofitt is offline   Reply With Quote

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 02:26 PM.


vBulletin ©2000 - 2009, Jelsoft Enterprises Ltd. Ubuntu Logo, Ubuntu and Canonical © Canonical Ltd. Tango Icons © Tango Desktop Project. lingonberry