You are not logged in.

#1 2006-09-28 17:01:01

mmccaskill
Member
From: NC
Registered: 2005-02-21
Posts: 165

/etc/profile question

Is it a good idea to give /sbin and /usr/sbin access to non-root users? Should there be a check for this?

Offline

#2 2006-09-28 21:31:29

tom.deb
Member
From: manchester/UK
Registered: 2005-06-20
Posts: 42
Website

Re: /etc/profile question

to me /sbin and /usr/sbin should not be in PATH, those binaries are so crucial you might want to be sure you run the correct one ! but I know it's OTT.

On a desktop were only trusted users have accounts, you can afford not to bother too much. On a server, take them out of your $PATH !


t o m d e b
_______________________________________
"the urge to destroy is a creative urge."
                                                 Mikhail Bakunin.

Offline

#3 2006-09-29 11:06:53

klapmuetz
Member
From: Germany
Registered: 2005-03-19
Posts: 75

Re: /etc/profile question

How about you try to look at the benefits you gain from putting /sbin and /usr/sbin only in the PATH to root users.

Pro:
  You inconvenience your user.
  (Non-legitimate ones)

Contra:
  You inconvenience your user.
  (Legimate ones)


Hello girls, I like rock climbing, mountain biking and rafting! Write me!

Offline

#4 2006-09-29 15:00:42

phrakture
Arch Overlord
From: behind you
Registered: 2003-10-29
Posts: 7,879
Website

Re: /etc/profile question

OMG klapmuetz is back? and posting on the forums? Armageddon is coming!

Offline

#5 2006-09-29 15:58:44

codemac
Member
From: Cliche Tech Place
Registered: 2005-05-13
Posts: 794
Website

Re: /etc/profile question

KLAPMUETZ!!!!

Come back to t3h irc.

Offline

#6 2006-10-02 09:17:49

klapmuetz
Member
From: Germany
Registered: 2005-03-19
Posts: 75

Re: /etc/profile question

I will.

But THEY fucked my Internet Connection. THEY are after me.

And check what they did to make the real-life satire complete:

  They installed an Access Point with MAC-Address Whitelisting and no WEP or WPA encryption.

BUT!

  They don't have any machine connected to that thing. Hence I can't see what MAC-Addresses are actually whitelisted. I cried night after night.

THEY fooled us all, especially you.


Hello girls, I like rock climbing, mountain biking and rafting! Write me!

Offline

#7 2006-10-02 11:54:17

allucid
Member
Registered: 2006-01-06
Posts: 259

Re: /etc/profile question

I have them in my path and I don't know of any adverse affects. Some commands can be partially used by users (such as ifconfig).

Offline

#8 2006-10-02 13:17:25

iphitus
Forum Fellow
From: Melbourne, Australia
Registered: 2004-10-09
Posts: 4,927

Re: /etc/profile question

klapmuetz wrote:

I will.

But THEY fucked my Internet Connection. THEY are after me.
And check what they did to make the real-life satire complete:
  They installed an Access Point with MAC-Address Whitelisting and no WEP or WPA encryption.
BUT!
  They don't have any machine connected to that thing. Hence I can't see what MAC-Addresses are actually whitelisted. I cried night after night.
THEY fooled us all, especially you.

kismet?

Offline

#9 2006-10-02 13:57:45

allucid
Member
Registered: 2006-01-06
Posts: 259

Re: /etc/profile question

klapmuetz wrote:

They installed an Access Point with MAC-Address Whitelisting and no WEP or WPA encryption.

BUT!

  They don't have any machine connected to that thing. Hence I can't see what MAC-Addresses are actually whitelisted. I cried night after night.

THEY fooled us all, especially you.

Start trying all MAC addresses sequentially. There's only 2^48. wink

Or try sniffing overnight.

Offline

#10 2006-10-04 09:31:07

klapmuetz
Member
From: Germany
Registered: 2005-03-19
Posts: 75

Re: /etc/profile question

iphitus wrote:

kismet?

I probably didn't express myself very clearly. kismet will not help me in this situation.
If nobody is using the AP, there is no traffic.
If there is no traffic, I can not read out MAC-Addresses. Hence I can not spoof them.

allucid:
I tried several nights... I guess it's just a wlanrouter that is used as a normal router/switch combination. That's what makes the story so lame. :-P

@Topic:

Sorry for Highjacking the thread. I won't do it again. I promise. :-P


Hello girls, I like rock climbing, mountain biking and rafting! Write me!

Offline

#11 2006-10-05 04:48:03

neotuli
Lazy Developer
From: London, UK
Registered: 2004-07-06
Posts: 1,204
Website

Re: /etc/profile question

I think the topic said thank you, but I'm not sure.

On another note, I don't think having sbin's in the path really makes any difference, after all... a regular user has very little power to really mess anything up, even if they are able to execute them.


The suggestion box only accepts patches.

Offline

Board footer

Powered by FluxBB