LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 02-03-2015, 10:07 PM   #16
veerain
Senior Member
 
Registered: Mar 2005
Location: Earth bound to Helios
Distribution: Custom
Posts: 2,524

Rep: Reputation: 319Reputation: 319Reputation: 319Reputation: 319

Well TBone I said that sarcastically.

Well If it's a one user system there is no security risk. If not it is.

Well seeing other console is a big security hole.

What if a root or other user with access to /dev/fbx views the console of other user when he/she is viewing passwords for example from a password manager which displays password or viewing a text with sensitive info.

With fbgrab command you can even save the snapshot of framebuffer and store it in a image file.

You don't have to be root. Just assigning the user to video group which has access to /dev/fbx is a security risk.

I think in TBone machine he sets /dev/vcs* and friends group to be accessed by multiple users by giving them video group perms.

If you can think then you know it's security risk. And I am issuing the security vulnerability report. You can find out in web search what's security issue if someone can view what you are viewing.
 
Old 02-04-2015, 08:46 AM   #17
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 26,636

Rep: Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965Reputation: 7965
Quote:
Originally Posted by veerain View Post
Well TBone I said that sarcastically.
Right...which is against LQ Rules.
Quote:
Well If it's a one user system there is no security risk. If not it is. Well seeing other console is a big security hole.

What if a root or other user with access to /dev/fbx views the console of other user when he/she is viewing passwords for example from a password manager which displays password or viewing a text with sensitive info.
...which goes back to "you restrict access to the console to START WITH, and that's not an issue, is it? Which was pointed out to start with. You DO NOT log in at the console for ANYTHING, except maintenance, and you restrict access to the computer room too. THAT is security layer one. Also, such things are GUI based...which a virtual console is NOT.
Quote:
With fbgrab command you can even save the snapshot of framebuffer and store it in a image file. You don't have to be root. Just assigning the user to video group which has access to /dev/fbx is a security risk. I think in TBone machine he sets /dev/vcs* and friends group to be accessed by multiple users by giving them video group perms.
What I do is have secure systems. This 'hole' is meaningless, and remains so. Again, NO ONE does serious sensitive work from the system console. If they do, you have MANY more security issues than the video group.
Quote:
If you can think then you know it's security risk. And I am issuing the security vulnerability report. You can find out in web search what's security issue if someone can view what you are viewing.
I can think very well, thanks...you appear to not be following what anyone else is saying, or the points they're making. And again, you mentioned SPECIFIC kernels...why don't YOU do the web search and provide the proof of this 'horror'??? You've been asked several times now, and still haven't. You say that *I* can "find out in web search", but I'm not the one trying to make this point...YOU ARE. Provide some proof, please.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Are there any Fonts need for Links2 (Web Browser) ? JESSEJJ89 Linux - Newbie 3 02-01-2013 08:56 PM
Failure to login from links2 web browser smeezekitty LQ Suggestions & Feedback 0 03-26-2011 01:12 AM
Does anyone have w3m browser or links2 package for slack? stormrider_may Slackware 9 03-14-2006 09:21 PM
links2 for slow internet users fakie_flip Linspire/Freespire 9 11-27-2005 11:28 AM
Permissions for browser and email client? eeried Linux - Security 4 06-18-2004 03:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 07:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration