From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Lars Ingebrigtsen Newsgroups: gmane.emacs.devel Subject: Re: Closing a privilege escalation Date: Thu, 26 Apr 2018 09:52:34 +0200 Message-ID: References: NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1524729082 31401 195.159.176.226 (26 Apr 2018 07:51:22 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Thu, 26 Apr 2018 07:51:22 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.0.50 (gnu/linux) Cc: emacs-devel@gnu.org To: Richard Stallman Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Thu Apr 26 09:51:17 2018 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fBbgT-000850-AU for ged-emacs-devel@m.gmane.org; Thu, 26 Apr 2018 09:51:17 +0200 Original-Received: from localhost ([::1]:40770 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fBbia-0002zl-8Q for ged-emacs-devel@m.gmane.org; Thu, 26 Apr 2018 03:53:28 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:54457) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fBbhv-0002xS-Kc for emacs-devel@gnu.org; Thu, 26 Apr 2018 03:52:52 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fBbhp-0001JZ-Vf for emacs-devel@gnu.org; Thu, 26 Apr 2018 03:52:47 -0400 Original-Received: from hermes.netfonds.no ([80.91.224.195]:50799) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fBbhp-0001IR-OW; Thu, 26 Apr 2018 03:52:41 -0400 Original-Received: from cm-84.212.221.165.getinternet.no ([84.212.221.165] helo=stories) by hermes.netfonds.no with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1fBbhi-0005Ah-7x; Thu, 26 Apr 2018 09:52:39 +0200 Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAGFBMVEX98+306eTx5uD++vDv 4dqcjIj67urm18/cKscKAAACIklEQVQ4jXWTQW/bMAyFCaTwXYKb86w6yTWDgZ1nT4uvQ1pOV2cH 7dxOjv7+Hik7S1HsJVAcfiIpyU80MxS8anCuMUWWFPCYMjTKkMbc7y9mAa2OOc8cOGS+xriCzHPI Y8jnPCPrBjAJM3VK4J+RqirSIHW9Vi9KOREhY3AWn0NAKMg35FmeIzlrrHOH/F7IcA6rbpAEjqdt hLSU/HNKTf2qYKIbwEYRznVvjCSAVAoQxfjI0xGBuwzbOGHMHXTUFrrc0sMe+CygQ06lpYbGieyO nxUchVS6waI5fFPQkZSq/gF+KnF0KcB7je/4zwoqJSv4zt0KaFKQNI4X9WMBtIDBtQV8OlbY5vFI pfvSfMdM1G+6zhVwW9WOX+iB6Kn78pWqyx2Y+TydflXNZ7IAE97tAjg09TZ6Z6aHKt6BA7+4tq5f kx/i6WJkWaQH9cje+Ysf/WjfAbeDR9+MT8n3+5O5AWvnDFCPeRz99mqMxEldzADJiXuT6WHoGxgB RieuS6E3ve5cwSEBeLg9AbiTnpaCGhk+CcHo95pR3CPXJst3fPMePsGRaIbTWtIIv0Nxo8y3rhUg zeXCNeI7OEjtI7WLcmrEj7SNF9uWDioUbLZ3AFejzM8riAAloMLTYJaboBnYm/ilxbqa7UTwxETR OKkV1Egz95E2nQJD8WJMW+41XzUM0OnByCH8xu2/blbfUfcfLYmbj+Aef8iA+26WXh/+AoTsAl8a 9XuEAAAAAElFTkSuQmCC In-Reply-To: (Lars Ingebrigtsen's message of "Thu, 26 Apr 2018 09:20:52 +0200") X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-Received-From: 80.91.224.195 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:224902 Archived-At: Lars Ingebrigtsen writes: > Richard Stallman writes: > >> The discussion reached the conclusion that the problem is real, even >> with recent GNU/Linux systems. We have not fixed it. > > I thought the discussion concluded that a sudo user can do anything > (like put stuff in root's ~/.bashrc), and that this isn't something that > Emacs should worry about. Oh, I see: The sploit here is that somebody has access to a user's account, but doesn't know what the user's password is? So they place something in the user's .emacs file that'll be run after the user does a sudo and then starts Emacs as root? Sounds kinda cumbersome when the attacker could just install a keylogger for the user and so on... -- (domestic pets only, the antidote for overdose, milk.) bloggy blog: http://lars.ingebrigtsen.no