Re: Java allows root access without permission?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



* Michael Cronenworth <mike@xxxxxxxxxx> [2010-10-27 16:34]:
> Kevin Martin on 10/27/2010 03:30 PM wrote:
> > What are the permissions for /opt?  Are you sure that the vpnagentd wasn't installed as part of some rpm?
> 
> No RPM was installed. I was not prompted by PackageKit or by any other 
> tool for my root password.
>

If you stop the agent, move the directory out of the way, and try the
applet again as a normal user, can you reproduce it? i.e. does the dir
appear again in /opt, owned by root, with the vpnagentd running as root
again?

Assuming PackageKit/RPM isn't involved, the only thing I can think of
that allowed this was either the browser being started as root without
realizing it, or something prompting you for the root password.

Cheers,
Deepak

> $ rpm -qa | grep -i cisco
> (no results)
> $ rpm -qa | grep -i vpn
> 
> $ ll /opt
> total 4
> drwxr-xr-x.  3 root root   16 Oct 27 11:16 cisco
> drwxr-xr-x.  3 root root   23 Oct  5 12:06 google
> drwxr-xr-x. 14 1000 1000 4096 Nov 30  2009 scratchbox
> 
> $ ll /opt/cisco/
> total 4
> drwxr-xr-x. 7 root root 4096 Oct 27 11:25 vpn
> 
> $ ll /opt/cisco/vpn/
> total 28
> -rw-r--r--. 1 root root 2267 Oct 27 11:16 
> anyconnect-Linux_64-2.5.1025-k9-11164927102010.log
> -r--r--r--. 1 root root 3958 Oct 27 11:16 AnyConnectLocalPolicy.xsd
> drwxr-xr-x. 2 root root 4096 Oct 27 11:26 bin
> drwxr-xr-x. 2 root root   53 Oct 27 11:16 lib
> drwxr-xr-x. 2 root root 4096 Oct 27 11:16 pixmaps
> drwxr-xr-x. 2 root root   91 Oct 27 11:16 profile
> drwxr-xr-x. 2 root root    6 Oct 27 11:16 script
> -r--r--r--. 1 root root    9 Oct 27 11:16 update.txt
> -r--r--r--. 1 root root  249 Oct 27 11:16 VPNManifestClient.xml
> -rw-r--r--. 1 root root  104 Oct 27 11:16 VPNManifest.dat
> 
> -- 
> users mailing list
> users@xxxxxxxxxxxxxxxxxxxxxxx
> To unsubscribe or change subscription options:
> https://admin.fedoraproject.org/mailman/listinfo/users
> Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines
-- 
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines

[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [EPEL Devel]     [Fedora Magazine]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Desktop]     [Fedora Fonts]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Fedora Sparc]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux