Ubuntu Forums Archive Viewer

[SOLVED] would like a reason, or chance to revise, locked thread

Archived thread 1006754 from Resolution Centre. Markdown source: Resolution_Centre/thread_1006754_[SOLVED]_would_like_a_reason,_or_chance_to_revise,.md

Original URL About this archive
#1

i recently posted a thread (http://ubuntuforums.org/showthread.php?p=6338293#post6338293) in regards to a program i'm working on. i was looking fr some simple anwsers, even just a no its not possible, or could you find another way to do this besides run as root. instead, i got a comment from p_quarles saying "There are ways of running as root without password authentication. This isn't something this forum can support, though, because as I said this is an enormously bad idea.

Run an SSH daemon and use that to poweroff. Alternatively, there is cron. Those are the sane ways to do what you want. E-mailing commands to your server is not."

and then, before i could reply with ways i was making it secure, he locked my thread. now, it may be just me, but i dont see that as fair, he could have asked me to revise my post, or told me another way to do what i wanted, or given me a chance to explain. i just wanted this to be brought to attention, thank you for your time in considering this. and no my intention is not just to be a problem user, i'm sorry if i come accross as such, i just want this to be delt with fairly.

#2

The staff member has posted a reason in the thread

I support the closure of the thread.

#3

KiwiNZ said: The staff member has posted a reason in the thread

I support the closure of the thread.

i appologize if i dont see the reason as sufficient, but i stand by my view.

#4

I appreciate your being polite. Thank you.

The reason that the answer is sufficient is because there are much better, commonly accepted, secure ways to do what you want to do. Emailing a root command to a server will either not work, or will involve making the server very insecure. Neither option is a good one. No matter what you do to try to secure your server, allowing any root commands to be sent in via email is a huge security risk and a very bad idea.

I support the staff member's decision.

#5

matthew said: I appreciate your being polite. Thank you.

The reason that the answer is sufficient is because there are much better, commonly accepted, secure ways to do what you want to do. Emailing a root command to a server will either not work, or will involve making the server very insecure. Neither option is a good one. No matter what you do to try to secure your server, allowing any root commands to be sent in via email is a huge security risk and a very bad idea.

I support the staff member's decision.

yes, but so what if i want to break from the mold? i thought this was what Cult of Mac did, tell people they cant do something. i'm sorry if you guys don't want to support me, but atleast it would be nice to be pointed to a place where i can get anwsers. i am aware of you polocies of the ubuntu security model (see http://ubuntuforums.org/archive/index.php/t-765414.html) but it does not state that you can't refer me to another place to get my anwser. i'm sorry if i've come accross as a little overbering or disrespectful, i do, but i would like if not a way to do what i am trying to do, i place to find out where there is. i do realise my idea is rather radical, and that it could possibly be insecure (if you would like me to send you my security steps so far then ask), but that's my problem, and will be delt with in turn. i promise all problems, both security and otherwise will be delt with in turn, but this is the topic right now to see if this approach is even viable, (wch it might not be even i will agree to that). right now i'm trying to make an idea work, which is what linux is all about from what i've studied, and i've been trying to find anwsers on the ubuntu forums, if thats against the rules, then tell me another way to do what i'm trying to do, or point me to another place (forums or otherwise) where i can get anwsers. i'm not trying to be disrespectful here or anything but i am a little peeved, for that i appologise. i do reiterate, if there is a way to do this that you know about, or you know another place for me to get anwsers, then tell me and i will stop posting about this, i promise.

#6

I think the fundamental problem with that thread is it quickly got steered in a very wrong direction involving extremely irresponsible/insecure things to do.

However, I should say that when properly designed there are ways to accomplish a remote shutdown in a reasonably secure manner, but that's not really where you steered the discussion.

With that said, I agree with the thread being closed.

If you want to discuss something along the lines of "Secure ways of remotely initiated shutdowns", that's a different matter and when you define your goals correctly you will see what the closing remark hinting to use a SSH daemon is probably the best answer you will find regarding this manner.

With that said, I agree with everyone else here. There is a responsibility of this forum to ensure advice given is safe and reasonable. Note that this is not the same thing as saying "you may not do this to your system" as you claim -- you can do whatever you want to do to your system, it's Open Source, but we at UbuntuForums will not condone users giving each other outrageously unsafe advice.

#7

jdong said: I think the fundamental problem with that thread is it quickly got steered in a very wrong direction involving extremely irresponsible/insecure things to do.

However, I should say that when properly designed there are ways to accomplish a remote shutdown in a reasonably secure manner, but that's not really where you steered the discussion.

With that said, I agree with the thread being closed.

If you want to discuss something along the lines of "Secure ways of remotely initiated shutdowns", that's a different matter and when you define your goals correctly you will see what the closing remark hinting to use a SSH daemon is probably the best answer you will find regarding this manner.

With that said, I agree with everyone else here. There is a responsibility of this forum to ensure advice given is safe and reasonable. Note that this is not the same thing as saying "you may not do this to your system" as you claim -- you can do whatever you want to do to your system, it's Open Source, but we at UbuntuForums will not condone users giving each other outrageously unsafe advice.

okay, thank you very much for giving me a clearly outlined, and concise treatise of why my thread was closed. and with that, goodbye.

#8

EDIT: a couple of posts appeared while I typed this one. Please ignore mine.

You know, your complaint is odd since you had a second thread on the exact same topic that was not closed (until just now).

http://ubuntuforums.org/showthread.php?t=1005653

You have been given great reasons why this is a bad idea by several people. You have also been given many other very good options. This qualifies as answering your initial question.

You have been answered by two admins in regards to your question as to why the thread was closed.

It's time to let it go. You won't get help doing something insecure here when there are safer ways to accomplish the task. I think your search for this specific request needs to move elsewhere.

#9

matthew said: EDIT: a couple of posts appeared while I typed this one. Please ignore mine.

You know, your complaint is odd since you had a second thread on the exact same topic that was not closed (until just now).

http://ubuntuforums.org/showthread.php?t=1005653

You have been given great reasons why this is a bad idea by several people. You have also been given many other very good options. This qualifies as answering your initial question.

You have been answered by two admins in regards to your question as to why the thread was closed.

It's time to let it go. You won't get help doing something insecure here when there are safer ways to accomplish the task. I think your search for this specific request needs to move elsewhere.

i would, like to point out that though they were about the same general topic, they are 2 very different things, one reading the body of a mesaage and sending it to terminal, the other, having a way to run a script with root privileges without having to enter a password, like say having a email activate a shell script to shut down my computer while i'm away, which is slightly more secure then just reading it off email. and yes i do agree it is time to let it go, which is why i'm going to stop posting threads about it. i do appreciate the time you've spent looking at my posts, and my thanks also goes out to the other admins who delt wiith this issue for solving it in a timely manner.

#10

I'm one of the resident security geeks of these forums, and I'd like to point out a couple things along your search:

(1) It absolutely is possible to grant 'sudo' access for a particular user to only a subset of commands.

(2) It's also possible to grant 'sudo' access without requiring a password.

(3) The astute reader has figured out at this point that he wants both (1) and (2) simultaneously.

(4) Be careful when granting sudo commands to understand the command COMPLETELY to ensure there isn't some hidden way of abusing the fact that this one command has root access to get more root access. For example, it should be obvious why giving root access to only an editor is probably as bad as giving root access to the whole system.

(5) When authenticating over e-mail or other plaintext protocols, consider the possibility of identity spoofing. E-mail is freely viewable and spoofable by a number of people along the way to its destination. What stops me from copying your e-mail and sending it to your system whenever I want to shut it down? What you probably want is some sort of "Challenge Response Authentication Protocol" -- Read up on http://en.wikipedia.org/wiki/Challenge_response for a gist of what that is.

(6) The lazy reader will note people have written extremely secure authentication systems for you, such as SSH.

The most straightforward, responsible solution is probably a SSH login account which has passwordless sudo access to the shutdown command, perhaps with 'sudo shutdown -h now' stuck in the user's .bashrc. Then use a secure form of authentication such as SSH with a strong password or public key authentication to give authorized users access to this account.

(7) Any time when you grant partial sudo access like this, it's again entirely possible for a user to severely abuse this level of access to do bad things to your system. It's often not simple to think through all the possible ways that this kind of access can be abused. Proceed with caution.

#11

and also, as it was probably a determining factor in the locking if my thread, the reason i wanted to use email, was not just because i could use any computer, it's also because i could use any cellphone, MID or PDA and even some MP3 players to be able to do things like shutdown, and restart my server, have somthing printed while i'm away from homw, or have coff being made while on my way home. i just thought it would be a very cool idea, so i wanted to persue if it could be implemented.

#12

das867 said: and also, as it was probably a determining factor in the locking if my thread, the reason i wanted to use email, was not just because i could use any computer, it's also because i could use any cellphone, MID or PDA and even some MP3 players to be able to do things like shutdown, and restart my server, have somthing printed while i'm away from homw, or have coff being made while on my way home. i just thought it would be a very cool idea, so i wanted to persue if it could be implemented.

The reason I suggested against e-mail was the problem with impersonation, as mentioned above. What you really need is a challenge-response protocol so that I cannot copy one of your shutdown requests word-for-word and expect that to work.

I still think what you are thinking of is a very neat idea and would be fun to write. I hope my ramble has helped you in formulating better questions to ask regarding how to do this other than granting a user free-for-all root access via e-mail.

#13

jdong said: I'm one of the resident security geeks of these forums, and I'd like to point out a couple things along your search:

(1) It absolutely is possible to grant 'sudo' access for a particular user to only a subset of commands.

(2) It's also possible to grant 'sudo' access without requiring a password.

(3) The astute reader has figured out at this point that he wants both (1) and (2) simultaneously.

(4) Be careful when granting sudo commands to understand the command COMPLETELY to ensure there isn't some hidden way of abusing the fact that this one command has root access to get more root access. For example, it should be obvious why giving root access to only an editor is probably as bad as giving root access to the whole system.

(5) When authenticating over e-mail or other plaintext protocols, consider the possibility of identity spoofing. E-mail is freely viewable and spoofable by a number of people along the way to its destination. What stops me from copying your e-mail and sending it to your system whenever I want to shut it down? What you probably want is some sort of "Challenge Response Authentication Protocol" -- Read up on http://en.wikipedia.org/wiki/Challenge_response for a gist of what that is.

(6) The lazy reader will note people have written extremely secure authentication systems for you, such as SSH.

The most straightforward, responsible solution is probably a SSH login account which has passwordless sudo access to the shutdown command, perhaps with 'sudo shutdown -h now' stuck in the user's .bashrc. Then use a secure form of authentication such as SSH with a strong password or public key authentication to give authorized users access to this account.

(7) Any time when you grant partial sudo access like this, it's again entirely possible for a user to severely abuse this level of access to do bad things to your system. It's often not simple to think through all the possible ways that this kind of access can be abused. Proceed with caution.

THANK YOU SO MUCH! i've been trying to find a way to do 3 things with this. 1. shutdown. 2. logoff 3. restart me server. and you have given me great assitance in this, so i thank you very much. and yes i am aware that an email address can be spoofed, but can the authentication code on a SIM card be? not without a lot of work, and physical access to my phone.

#14

oh and i just noticed, why can't you give people thanks in here? i would give you some but theres no button, sorry.

#15

Why do I have to gain access to your phone to fake an e-mail from you? :)

#16

jdong said: Why do I have to gain access to your phone to fake an e-mail from you? :)

because otherwise it would take some very specialized equipment to spoof it, atts networks are actually pretty secure.

#17

This is off topic for the resolution center and more for underground alt.2600 type sites, but I won't go into my previous affiliations before UbuntuForums but I will say be careful with such assumptions ;-)

#18

jdong said: This is off topic for the resolution center and more for underground alt.2600 type sites, but I won't go into my previous affiliations before UbuntuForums but I will say be careful with such assumptions ;-)

good to know then, haha! and thanks again for your help!

#19

jdong said: This is off topic for the resolution center and more for underground alt.2600 type sites, but I won't go into my previous affiliations before UbuntuForums but I will say be careful with such assumptions ;-)

also i know its kind of a noobie thing to ask, but can you explain how to edit .bashrc to give 1 command root access, lets say sudo shutdown -h 1. i know you probably don't want to anwser, but if you could post the anwser or PM me or email me that would be awesome, or ban me that'd be okay to, and don't worry i'm already working on some security features, i'm not going to be a complete idiot and go overboard with this. you dont even have to give me the anwser, you could just point me to somewhere to get it, that would be great to.

#20