[TAG] pppd changing file permissions (Was Re: lpr works for user not root in Basiclinux 2.1)

sindi keesan keesan at sdf.lonestar.org
Wed Mar 28 20:34:08 MSD 2007


>
>> I doubt we have log files.
>
> Then I can only wish you the best of luck in troubleshooting your
> problems. I've never been good at running with both my feet tied in a
> sack.


> -- 
> * Ben Okopnik * Editor-in-Chief, Linux Gazette * http://LinuxGazette.NET *
>


'Strace eznet up 4' when run as user indicates that eznet run as user does 
not have permission to access /var/eznet/eznet.conf or any other files in 
/var/eznet (which are log files kept for five different sessions such as 
ppp.0 pid.0 status.0 and sessions.html).  But eznet is root suid so I 
thought it had root permissions to access everything.

eznet.conf contains password so I don't want it to be user-readable.

Online eznet documentation does not help, nor can I understand the 130 
pages of source code for eznet.  Nobody else seems to have had problems 
dialing as user with eznet.

-rws--s--x root root  eznet

I can make it work by changing /dev/ttyS1 to user-writeable (every time 
before logging in as user, or probably in an rc file).

The error message when I try to dial as user with eznet says I don't have 
permission to access /dev/ttyS1 (or other modem device).

I put pppd back to non-suid and non-executable by user since eznet is what
runs it. I should not work on linux late at night.

Another approach would be to use pppd without eznet, but then the friends 
I set up linux for would need to learn to use it too (or come back to me 
whenever they changed user information).

Similar problems for both versions of Basiclinux.

I can dial as root and then do everything else as user.  I think this is 
how we were told to go online for added security.  How exactly would 
dialing as root compromise security?  We have no open ports.

Maybe Karolis can figure this out.

Sindi

keesan at sdf.lonestar.org
SDF Public Access UNIX System - http://sdf.lonestar.org




More information about the TAG mailing list