Re: Debian 5 security issue



On 2010-03-09 21:46, Bret Busby wrote:
Hello.

In running sybaptic, to check for available system updates, I encountered the following message, and it is not the first time that I have encountered the message.

"Granted permissions without asking for password

I think this is specific to this one user.

The '/usr/sbin/synaptic' program was started with the privileges of the root user without the need to ask for a password, due to your system's authentication mechanism setup.

It is possible that you are being allowed to run specific programs as user root without the need for a password, or that the password is cached.

This is not a problem report; it's simply a notification to make sure you are aware of this."

I have not knowingly configured the system to institute this system security breach.

At some point, "it" must have prompted you for the keyring passphrase, and you clicked "never ask me this again".

How do I eliminate

Don't know.

this system security breach?


http://en.wikipedia.org/wiki/Hanlon%27s_razor


--
Ron Johnson, Jr.
Jefferson LA USA

"If God had wanted man to play soccer, he wouldn't have given
us arms." Mike Ditka


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx
Archive: http://lists.debian.org/4B974194.1050201@xxxxxxx



Relevant Pages

  • Re: Affecting Institutional Change (Yeah Right)
    ... asking for a copy in plain text? ... despite giving them a nice explanation the first time ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: [OT] Re: Debian User List
    ... why they need things like Second Life in the first place. ... These things might be fun the first time, ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Lenny + Dell PE 2970
    ... Is it imperative for you to stick with GRUB? ... I did try LILO the first time it happened and it failed to work as well. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)
  • Re: Re: samba domain controller
    ... failing to resolve the name pdc.bollocks.com, even though it was able to ... I can see the shares and navigate them. ... I have a root user with a password. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Debian 5 security issue
    ... The '/usr/sbin/synaptic' program was started with the privileges of the root user without the need to ask for a password, due to your system's authentication mechanism setup. ... I have not knowingly configured the system to institute this system security breach. ... published by Pan Books, 1992 ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)