You are not logged in.

#1 2006-06-21 19:55:25

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

What is it with these distros?

Okay, SLAX is very nice, but I absolutely refuse to run my desktop as root! At least turn off the root account and have an admin account with sudo priveleges ala Ubuntu, or something...

(Also, I must remember to tell the SLAX devs that no vi makes sudo annoying to change the settings on.)

Edit: right, CUPS would be a problem wouldn't it. Anyone know how Ubuntu handles CUPS administration with the root account disabled?

Offline

#2 2006-06-21 20:17:56

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: What is it with these distros?

gtksudo
and
kdesu

pretty sure that is what the helper apps are called..


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#3 2006-06-21 21:00:40

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

Re: What is it with these distros?

No sudo support for KDE?

Offline

#4 2006-06-21 21:06:37

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: What is it with these distros?

kdesu is the same thing..i might even have the name wrong..maybe it is kdesudo or something..
it does the same thing..just a different name...again..not sure. I haven't used kde in years.


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#5 2006-06-21 21:13:49

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

Re: What is it with these distros?

Weird. Last time I used KDE I had to give the root password to do CUPS administration, and the root account needed to be unlocked.

Offline

#6 2006-06-21 21:19:13

Dusty
Schwag Merchant
From: Medicine Hat, Alberta, Canada
Registered: 2004-01-18
Posts: 5,986
Website

Re: What is it with these distros?

Gullible Jones wrote:

Weird. Last time I used KDE I had to give the root password to do CUPS administration, and the root account needed to be unlocked.

you're too quick to judge and assume anything that happens to you is the only way it can happen.    

For the record, Kubuntu permits cups administration using sudo somehow. It always asks a user with admin privleges for that user's password, not a root password.  Kubuntu, BTW, uses KDE.

It reflects poorly on yourself and on this community when you make sweeping statements without checking the facts. It is never safe to assume that the way things run for you is the way they are for all users, or that your partial knowledge encompasses all that can be known.

Dusty

Offline

#7 2006-06-21 21:22:32

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

Re: What is it with these distros?

Wow, I can't believe I never noticed that SLAX has SSHD running by default too. Default root login plus weak password plus SSHD running by default... Is this not a bit like painting a huge bullseye on one's chest and screaming "Shoot me!" to every script kiddie on the planet? :shock:

Offline

#8 2006-06-21 21:48:38

Dusty
Schwag Merchant
From: Medicine Hat, Alberta, Canada
Registered: 2004-01-18
Posts: 5,986
Website

Re: What is it with these distros?

Have you been hacked using this setup yet?

Offline

#9 2006-06-21 22:11:55

cactus
Taco Eater
From: t͈̫̹ͨa͖͕͎̱͈ͨ͆ć̥̖̝o̫̫̼s͈̭̱̞͍̃!̰
Registered: 2004-05-25
Posts: 4,622
Website

Re: What is it with these distros?

slax is a live CD, isn't it?


"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍

Offline

#10 2006-06-21 23:19:08

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

Re: What is it with these distros?

Yes it is.

Dusty wrote:

you're too quick to judge and assume anything that happens to you is the only way it can happen.

For the record, Kubuntu permits cups administration using sudo somehow. It always asks a user with admin privleges for that user's password, not a root password. Kubuntu, BTW, uses KDE.

It reflects poorly on yourself and on this community when you make sweeping statements without checking the facts. It is never safe to assume that the way things run for you is the way they are for all users, or that your partial knowledge encompasses all that can be known.

Dusty

What sweeping statements? Look, sorry if you read any sarcasm into what I said earlier, that's not the way I meant it...

Have you been hacked using this setup yet?

No but I haven't been running things from the root account.

Offline

#11 2006-06-22 16:25:52

whargoul
Member
From: Odense, Denmark
Registered: 2005-04-04
Posts: 546

Re: What is it with these distros?

The scary is, that I think SLAX mounts all your disks.


Arch - It's something refreshing

Offline

#12 2006-06-22 17:42:55

Mr Green
Forum Fellow
From: U.K.
Registered: 2003-12-21
Posts: 5,896
Website

Re: What is it with these distros?

op


Mr Green

Offline

#13 2006-06-22 18:29:05

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

Re: What is it with these distros?

It does mount all your disks on boot. Or tries to anyway, I'm not sure how it handles NTFS.

Offline

#14 2006-06-22 21:39:07

whargoul
Member
From: Odense, Denmark
Registered: 2005-04-04
Posts: 546

Re: What is it with these distros?

Gullible Jones wrote:

It does mount all your disks on boot. Or tries to anyway, I'm not sure how it handles NTFS.

So we actually have a very unsecure dist. Somebody could erase my disk just like that. :shock:


Arch - It's something refreshing

Offline

#15 2006-06-22 21:59:05

phrakture
Arch Overlord
From: behind you
Registered: 2003-10-29
Posts: 7,879
Website

Re: What is it with these distros?

whargoul wrote:

So we actually have a very unsecure dist. Somebody could erase my disk just like that. :shock:

Not entirely true.  They could be mounted read-only.  Also, if you're running as a normal, non-root user, there's no difference between having your disks mounted via a live CD or via the normal system.

You can make the same claim about a normal arch install. "Oh god someone can gain root permissions and erase my disks!" - yeah, this has *always* been possible.

Offline

#16 2006-06-22 23:13:05

kth5
Member
Registered: 2004-04-29
Posts: 657
Website

Re: What is it with these distros?

once somebody has physical access to your box, every meassure is more or less useless.


I recognize that while theory and practice are, in theory, the same, they are, in practice, different. -Mark Mitchell

Offline

#17 2006-06-23 01:54:55

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

Re: What is it with these distros?

The issue here isn't physical access.

(I don't really see how it would matter if SLAX automounts your partitions, someone with remote access could do that themselves, or just format your hard drive.)

Offline

#18 2006-06-23 02:03:21

Dusty
Schwag Merchant
From: Medicine Hat, Alberta, Canada
Registered: 2004-01-18
Posts: 5,986
Website

Re: What is it with these distros?

In fact, there is no issue here.

Offline

#19 2006-06-23 08:30:01

ScriptDevil
Member
From: In Front of My PC
Registered: 2006-04-06
Posts: 253

Re: What is it with these distros?

the best thing to do sitting in front of a person you want to have revenge on -No, not format it. Remove the hard disk and any other part, and take it home wink


Be yourself, because you are all that you can be

Offline

#20 2006-06-23 08:30:50

ScriptDevil
Member
From: In Front of My PC
Registered: 2006-04-06
Posts: 253

Re: What is it with these distros?

You can possibly keep the computer in a back locker for Safety sake( especially from me )


Be yourself, because you are all that you can be

Offline

#21 2006-06-23 10:42:43

Sigi
Member
From: Thurgau, Switzerland
Registered: 2005-09-22
Posts: 1,131

Re: What is it with these distros?

Mr Green wrote:

op

op <- more info here


Haven't been here in a while. Still rocking Arch. smile

Offline

#22 2006-06-23 14:19:23

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

Re: What is it with these distros?

That's not much info, and the project's homepage is 404. :?

Offline

#23 2006-06-26 20:47:07

Bison
Member
From: Jacksonville, FL
Registered: 2006-04-12
Posts: 158
Website

Re: What is it with these distros?

Slax is a live cd.  It doesn't even have an hd install AFAIK.  So if someone puts in ANY livecd into your pc, there is no local security.

Offline

#24 2006-06-26 22:26:00

Gullible Jones
Member
Registered: 2004-12-29
Posts: 4,863

Re: What is it with these distros?

My issue was with remote security, not local security. Perhaps I am wrong, but I figured that they could at least leave sshd off by default.

(Wait a minute... It's a live CD. Come to think of it, why would you have the OpenSSH daemon  running on a live CD? Hmm. Maybe it's supposed to be a safeguard against X borking and locking the machine up locally?)

BTW, SLAX can be installed to the hard drive. Not sure how its security stuff is there though, probably much better.

Offline

#25 2006-06-27 19:49:58

Bison
Member
From: Jacksonville, FL
Registered: 2006-04-12
Posts: 158
Website

Re: What is it with these distros?

I'm guessing sshd doesn't matter, because your isp will likely block the port.  Even if it doesn't, you have to set up your router forwarding.

I'm with jones here though.  Why would you have sshd running on a live cd?

Offline

Board footer

Powered by FluxBB