Re: Insidious Spam/swen/Garbage

From: Monique Y. Herman (spam_at_bounceswoosh.org)
Date: 10/26/03

  • Next message: Monique Y. Herman: "Re: Insidious Spam/swen/Garbage"
    To: debian-user@lists.debian.org
    Date: Sun, 26 Oct 2003 14:55:16 -0700
    
    

    On Sun, 26 Oct 2003 at 21:29 GMT, Wayne Topa penned:
    > Monique Y. Herman(spam@bounceswoosh.org) is reported to have said:
    >>
    >> Of course, your password will then be in plain-text in a file. If
    >> you are the only person with root access, this probably isn't a big
    >> deal until your box gets hacked, but this sort of thing always gives
    >> me the willies.
    >
    > You runs mutt as root? That would give me the wilies! I assumed that
    > no one would try that!

    Did I imply that?

    I meant to say, anyone with root access could view your password. If
    you are the only person with root access, this probably doesn't matter.

    I don't run mutt as root, but how would that be any more dangerous than
    running, say, cat or vi as root?

    >
    > I, of course, meant the instructions as a suggeation for the users
    > .muttrc. If you run mutt as root I have no advice other then, don't.
    >
    > So what do you do about your /etc/ppp/pap-secrets file? It has the
    > same permissions as the your root .muttrc? Get hacked and it's just as
    > bad.

    Well, I don't use dialup, so it's not a problem. I assume pap-secrets
    has your dialup password or something in it? If so, and if you use a
    unique password for dialup, then I would think the worst that could
    happen is that they could use the dialup access that is legitemately
    yours. If your ISP bundles email and web hosting, that would be a
    problem, too. Having someone steal my bandwidth doesn't frighten me
    nearly as much as having someone read or destroy my mail.

    It's the age-old problem of security vs. convenience. I remember using
    a vpn client for work that insisted on putting its configuration file
    (including password) in /etc, and furthermore installed it
    world-readable by default. Fortunately, it still ran after you
    restricted its permissions ... Now, sure, I did restrict its
    permissions, and iirc we actually had access to the source, so I could
    have modified it to read the configuration from elsewhere ... but still,
    the default configuration was just bad, bad, bad.

    It would probably be more secure (assuming some kind of encryption) to
    enter your password every time you want to check mail, but most of us
    are willing to sacrifice some security to avoid having to type our
    passwords all the time. Even so, it's better to make a conscious choice
    *after understanding the implications* than to just blindly sally forth.

    -- 
    monique
    Unless you need to share ultra-sensitive super-spy stuff with me, please
    don't email me directly.  I will most likely see your post before I read
    your mail, anyway.
    -- 
    To UNSUBSCRIBE, email to debian-user-request@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Monique Y. Herman: "Re: Insidious Spam/swen/Garbage"

    Relevant Pages

    • Re: root | su
      ... him why what he's doing is improper or foolish, or simply pull his root ... If this is a work-related incident, talk to your boss ... complete tool -- imagine Dilbert's boss with basic UNIX CLI and "how to ... didn't have root access to determine what the problem was, ...
      (freebsd-questions)
    • Re: Emergency! please help with file system access issue
      ... My friend was a security expert so I am sure ... > you now have root access and can change the password. ... Some systems are configured to ask for root password if you type "linux 1". ...
      (comp.os.linux.security)
    • Re: Choosing a distribution
      ... 'sudo bash' where I haven't had a proper root account to work with. ... cracked and hence give the intruder root access. ...
      (Ubuntu)
    • RE: [SLE] root access to user
      ... Can I pick on one thing about giving root access to users. ... the user will be prompted for the root password. ... You can do all this in Samba, but unless you are using at least one of ...
      (SuSE)
    • Re: [Full-disclosure] oh oh 0 day - MyTV/x Version 3.6.6 & 4.0.8 for MyTV.PVR allows loc
      ... recording can be used to leverage root if I remember correctly. ... If there is a CERT Vulnerability tracking number please put it ... bypass and root access on Apple Mac OS X. ... and verify that root access had been gained. ...
      (Full-Disclosure)