Security problems with sudo

Thiago Macieira thiago at kde.org
Sun May 17 15:16:42 BST 2009


John Tapsell wrote:
>So create an ssh binary as well in the home directory :-D

If you run infected programs, it's your own fault.

This case would be no different then an ugly dialog box saying "I'm a 
virus, please type your root password now" and the user doing it.

SAK wouldn't work here. If you're ssh'ing to root on a remote machine, how 
is that remote machine going to grab your keyboard?

-- 
  Thiago Macieira  -  thiago (AT) macieira.info - thiago (AT) kde.org
    PGP/GPG: 0x6EF45358; fingerprint:
    E067 918B B660 DBD1 105C  966C 33F5 F005 6EF4 5358
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part.
URL: <http://mail.kde.org/pipermail/kde-core-devel/attachments/20090517/d4048610/attachment.sig>


More information about the kde-core-devel mailing list