D12732: Implement a more user-friendly run-as-root-or-sudo behavior

Nathaniel Graham noreply at phabricator.kde.org
Tue May 8 13:54:27 BST 2018


ngraham added a comment.


  In D12732#259518 <https://phabricator.kde.org/D12732#259518>, @markg wrote:
  
  > So what is the real bug.. Well, this quote describes it:
  >
  > > Now I sat down and implemented the attached exploit. The key idea is to use an 
  > >  embedded konsole window in a root owned process and send it key events. See 
  > >  the attached README as well.
  >
  > That is from the before mentioned link on marc.info.
  >
  > Why is that an exploit again? You are root to gain root... **you are root already!**
  >  I don't see why that is a bug.
  
  
  I still have not seen  this objection addressed at all...

REPOSITORY
  R318 Dolphin

REVISION DETAIL
  https://phabricator.kde.org/D12732

To: ngraham, #dolphin, graesslin
Cc: emmanuelp, zzag, nicolasfella, elvisangelaccio, Fuchs, mmustac, markg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mail.kde.org/mailman/private/kfm-devel/attachments/20180508/b4f99071/attachment.htm>


More information about the kfm-devel mailing list