Re: Reinstalling xwindow

From: Charles Burnaford (crb_at_nb.net)
Date: 04/04/05


Date: Mon, 04 Apr 2005 00:48:48 -0400

When you select a function under yast, It will ask for the root password
if the function needs it

Charles Burnaford
crb@nb.net

houghi wrote:
> Sreeram Koneru wrote:
>
>>That will /sbin/yast not just yast
>
>
> I just checked and when I do '/sbin/yast' or '/sbin/yast2' it does NOT
> ask for a password. Holy crap. That is a serious security leak. It means
> that anybody can change settings and really has root privelages.
>
> OK, a lot of things are not possible, but still I think it is extremely
> dangerous. There are several reasons this is dangerous. When you start
> yast normaly, you are asked for a pasword. This gives me the idea that
> that is part of the yast check. It is not. :-(
>
> I was not able to do anty real changes, but it still wories me a bit.
> I have not tried all posibilaties, so I am not sure if it is possible or
> not.
>
> I run SUSE 9.1
I



Relevant Pages

  • Re: [opensuse] 11.0 and new behavior of kdesu
    ... For me yast works (providing the root password), ... backports and the "non-oficial" kde3 ... repositories, and I had at least the same version of kde, and there it ...
    (SuSE)
  • Re: Yast Software Management closing
    ... They thought the security of having to enter the root password everytime ... the check-box to make it remember the password for that session. ... unless you close the main YaST window and need to ... The first time I started YaST up on my PPC system, ...
    (alt.os.linux.suse)
  • Re: [SLE] editing root files
    ... root, which isn't that hard for you, as you have the root password, no? ... I conffess I have not looked into all the new things yast ... tho I have read in linux-magazine as well as Linux magazine ( ... magazine, should you like it's tone ("can do" rather than, well it's ...
    (SuSE)
  • Re: [SLE] HOWTO keep the root password in yast
    ... > do you know how to keep the root password in yast? ... > there is a radio button but it never work ... ... to YaST, for example,) and only for a specified period. ... Check the headers for your unsubscription address ...
    (SuSE)