Java allows root access without permission?

Deepak Bhole dbhole at redhat.com
Wed Oct 27 20:49:12 UTC 2010


* Michael Cronenworth <mike at cchtml.com> [2010-10-27 16:34]:
> Kevin Martin on 10/27/2010 03:30 PM wrote:
> > What are the permissions for /opt?  Are you sure that the vpnagentd wasn't installed as part of some rpm?
> 
> No RPM was installed. I was not prompted by PackageKit or by any other 
> tool for my root password.
>

If you stop the agent, move the directory out of the way, and try the
applet again as a normal user, can you reproduce it? i.e. does the dir
appear again in /opt, owned by root, with the vpnagentd running as root
again?

Assuming PackageKit/RPM isn't involved, the only thing I can think of
that allowed this was either the browser being started as root without
realizing it, or something prompting you for the root password.

Cheers,
Deepak

> $ rpm -qa | grep -i cisco
> (no results)
> $ rpm -qa | grep -i vpn
> 
> $ ll /opt
> total 4
> drwxr-xr-x.  3 root root   16 Oct 27 11:16 cisco
> drwxr-xr-x.  3 root root   23 Oct  5 12:06 google
> drwxr-xr-x. 14 1000 1000 4096 Nov 30  2009 scratchbox
> 
> $ ll /opt/cisco/
> total 4
> drwxr-xr-x. 7 root root 4096 Oct 27 11:25 vpn
> 
> $ ll /opt/cisco/vpn/
> total 28
> -rw-r--r--. 1 root root 2267 Oct 27 11:16 
> anyconnect-Linux_64-2.5.1025-k9-11164927102010.log
> -r--r--r--. 1 root root 3958 Oct 27 11:16 AnyConnectLocalPolicy.xsd
> drwxr-xr-x. 2 root root 4096 Oct 27 11:26 bin
> drwxr-xr-x. 2 root root   53 Oct 27 11:16 lib
> drwxr-xr-x. 2 root root 4096 Oct 27 11:16 pixmaps
> drwxr-xr-x. 2 root root   91 Oct 27 11:16 profile
> drwxr-xr-x. 2 root root    6 Oct 27 11:16 script
> -r--r--r--. 1 root root    9 Oct 27 11:16 update.txt
> -r--r--r--. 1 root root  249 Oct 27 11:16 VPNManifestClient.xml
> -rw-r--r--. 1 root root  104 Oct 27 11:16 VPNManifest.dat
> 
> -- 
> users mailing list
> users at lists.fedoraproject.org
> To unsubscribe or change subscription options:
> https://admin.fedoraproject.org/mailman/listinfo/users
> Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines


More information about the users mailing list