D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] setuid-root



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Kai Hendry wrote:
> On Wed, Jan 08, 2003 at 11:55:37PM +0000, Simon Waters wrote:
>
>>Redhat have a setuid usernetctl, thats how I get around it,
>>which establishes if the ifcfg-pppN script permits users to do
this.
>
>
> I am aware of the scripts to get around this. ifup ppp0 etc,
however I
> don't want to use these scripts, I want to use kppp, which
requires
> permission with pppd.

Ah, kppp can also be made setuid root, should be in the online
help, again Redhat bypass this for security reasons and use
"console helper", so I can us "ifup pppN" N=0,1,2,3 as an
ordinary user (via setuid usernetctl), but kppp on Redhat
requires the root password (by default).

> kppp is a great dialer. For example you can easily smack in
dialup info
> for more than one ISP, and along with that, more than one
number for
> each ISP. I want this setup, as dialups are unreliable.

Unreliable - in what way?

>>I suspect the alternative is a setuid pppd, which is discussed
>>in the pppd manual page - yuk.
>
>
> Does that require re-compilation ?

Just chmod afaik, I haven't tried it in Debian yet.

> p.s. hate redhat

Yes, but they do seem to have tried to minimise the code that is
run setuid, although I think the effort would have been better
spent restructuring Linux along the lines the NSA took, but that
is easy to say when you don't have to write the code or win the
political battles.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQE+HXAGGFXfHI9FVgYRAijbAJ4haPOtFXd4mQYGCW0sfVFp3HH9kgCgiDzp
ZYtJnklQ66b3VQ+feUNYbgE=
=m6Af
-----END PGP SIGNATURE-----

--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe.


Lynx friendly