[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: localeconf package



On 17 Feb 2002 19:57:25 -0500
Jeff Licquia <licquia@debian.org> wrote:

> Uh... I use gnome-sudo every day for an unrelated thing, and it works
> fine for me.
sure, but you are allowed to run /usr/lib/gnome-sudo/gnome-sudo-helper
with sudo, right?

> 
> gnome-sudo-helper is a shell script that sets up X stuff before calling
> any program you pass it, yes.  OTOH, it's a simple shell script,
> non-setuid (as if that would work anyway).  You still need to gain root
> via some other method; if you can do that, you don't need
> gnome-sudo-helper (unless your l33t programz need an X display).
yes, I know it... now let's see what we can do with it:

[/usr/lib/gnome-sudo]
[kov]@[couve] $ mkdir /tmp/a
[/usr/lib/gnome-sudo]
[kov]@[couve] $ sudo `pwd`/gnome-sudo-helper /tmp/a /bin/sh
GNOME_SUDO_DONE sh-2.05a# 

tchan! I'm now root, with no effort... this is a root hole, I may be wrong,
anyway, and you don't need to be able to exec gnome-sudo-helper as
root with sudo, but how do you get gnome-sudo to work then?

> > is it that difficult to use su instead of sudo? I think it is a lot
> > safer and a lot more user friendly
> 
> The configlets need a way to run programs as root (specifically debconf
> stuff and the postinsts of the programs they configure).  Any way they
> can do that is fine.
> 
> Unfortunately, the only way I know of to ask for the root password via
> an X window halfway safely (and without the ugliness of "xterm -e") is
> with gnome-sudo.  If you have any better ways, let me know.
sure I know it, what I mean is: would it be difficult to hack a 'gnome-su'
instead of 'gnome-sudo'? that would be more user friendly, IMO, as
one would not have to mess with /etc/sudoers... I'll take a look at
kdesu

[]s!

-- 
    Gustavo Noronha Silva - kov <http://www.metainfo.org/kov>
*---------* -+-+--+-+--+-+--+-+--+-+--+-+--+-+--+-+--+-+--+-+-+
|  .''`.  | Debian GNU/Linux: <http://www.debian.org>         |
| : :'  : + Debian BR.......: <http://debian-br.cipsga.org.br>+
| `. `'`  + Q: "Why did the chicken cross the road?"          +
|   `-    | A: "Upstream's decision." -- hmh                  |
*---------* -+-+--+-+--+-+--+-+--+-+--+-+--+-+--+-+--+-+--+-+-+



Reply to: