On CBS.com: Get More On Amazing Race Eliminated Team
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 8 of 34:
Next »
« Previous
This is dangerous
Gotta be root. This is a good thing and helps Linux/Unix to avoid some of the goofy things that happen in Windows.

Can you specify? I'm not aware of any issues with installing Windows programs as a non-administrator. Although most simply stop you right at the beginning, the ones that have completed successfully worked just fine for me.

Many, including me, enjoy the intergration of Windows but one of the unintended side effects is that apps can install with plain old user rights

As the administrator of my computer system, I can install an application that I'm not too sure about by logging in under a restricted account in Windows. If the installer ends up being a trojan, it can't do too much damage. The ability to install apps with "plain old user rights" is a good thing from an administrator point of view.

In the end, an installation program is nothing more than an executable that puts files on the hard drive and updates a database. I don't see why it is okay that Linux allows me to run all executables/scripts as a restricted user except installation scripts like RPMs. It seems like a perfect way of using social engineering to trick a user into running anything I want them to as root. If they are used to installing all RPMs as root, they won't mind running the FREE DANCING ELVES.rpm as root either. Once they've done that, their machine is mine. I can mess with their firewall, install back door servers, etc.

What's even more dangerous is that my default SuSE installation asks me if I want to use YaST to install .rpm links when I click on them in Konqueror. If I say yes, I must supply my root password (since you say I can't use a restricted account) and *poof*, an rpm trojan has taken over my Linux machine. I haven't gone to the command line and I haven't typed chmod +x. When Joe Sixpack starts using Linux, and standard operating procedure is to type his root password every time he installs a new .rpm, he won't blink twice just because the .rpm is called FREE DANCING ELVES.rpm.
Posted by: NonZealot   Posted on: 03/22/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

That's entrapment!!!  Xunil_Sierutuf | 03/22/05
Although you are always NWOR...  NonZealot | 03/22/05
Confirms what I've found.  Anton Philidor | 03/22/05
I've found the XP Firewall  voska | 03/22/05
I agree  Henaway | 03/22/05
Question about installing RPM as root  NonZealot | 03/22/05
Gotta be root  Sunny Jalolly | 03/22/05
This is dangerous  NonZealot | 03/22/05
Many folks have spyware loaded via IE browser  Sunny Jalolly | 03/22/05
Rebuttal  NonZealot | 03/22/05
Let us review your logic, OK?  Sunny Jalolly | 03/22/05
Ditto  ac2_z | 03/22/05
Entrapment  RicD_ | 03/22/05
Defined  Anton Philidor | 03/22/05
Operating systems protect against stupidity?  Anton Philidor | 03/22/05
Operating systems protect against stupidity?  RicD_ | 03/22/05
So Operating Systems do protect the dumb  nucrash | 03/22/05
A good security model from the get go  Sunny Jalolly | 03/22/05
If you ain't on my buddy list...  BitTwiddler | 03/22/05
That's fine for us adults  Michael Kelly | 03/22/05
Wild parties at 2am are probably safer for them than the Internet happy  BitTwiddler | 03/22/05
My Kids Get It, You Need to Try Harder  ray916mn@... | 03/22/05
Not always effective...  Bibers | 04/14/05
What amazes me...  BitTwiddler | 03/22/05
What you're saying is Billy and Ballmer should..  Xunil_Sierutuf | 03/22/05
Unknowing end users are the main conduit for IM disasters  Sunny Jalolly | 03/22/05
IM Status - security?  stevem_001 | 03/22/05
Right on!  Sunny Jalolly | 03/22/05
But  Omch'Ar | 03/22/05
Bwahahaha  Sunny Jalolly | 03/22/05
ISO: articles about IM dangers and ways to use safely  lvirden@... | 03/22/05
Computer Security is Insignificant  ray916mn@... | 03/22/05
Invent a foolproof system and only a fool would use it!  osreinstall | 03/23/05
IM viruses  rachmiel613 | 03/23/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Meet Doc