Fedora Security :: How To Add Special Authority
May 30, 2009I give access all the groups adm, im, etc. but when I try to run the visudo command the system don't let since I dont have privilege.
View 7 RepliesI give access all the groups adm, im, etc. but when I try to run the visudo command the system don't let since I dont have privilege.
View 7 RepliesI just got a pop up that said that there is a Firefox Ubdate that I do not have the authority to install. It gives a link of www.firefox.com to go to for the latest firefox. I checked the Update manager. No update. All of Mozilla links in google say Mozilla. I feel sure this is an attempt to install malware. It came up when I went to cnet and I guess I shoule include a picture of it. Does anybody have any experience with this?
I went on to read cnet and the first article was about major add servers serving up adds that automaticly install malware. I guess this was a case of that. I had addblocker disabled at the time but noscript active. Looks to me like having noscript saved me an infection. Be careful out there.
I have changed my username in my fedora 11. on the next restart it asks for a login with my new username but when I enter my password it gives a errror "could not update ICE autority file/home/shubhra/ICE authority" when i click ok a next error comes "There is a problem with your configuration server(/usr/libexe/gconfg/sanity)" on clicking OK to this error a the blank screen comes with mouse pointer on it.
View 1 Replies View RelatedI just erased WinXp and installed Ubuntu on old laptop. I intend to use it later ot connect to public Wi-Fi. Do i need to install a firewall GUI and make any special settings? I didn't encrypt home folder during installation. I probably should have done it. But i am already low on system resources (224MB ram, 1.2Ghz CPU). Would that use up any additional resources? Would it make computer run slower? Can i still encrypt the home folder after i installed the system?
View 3 Replies View RelatedI'm trying to use ssh-keyscan to get some known_host file population going on, but I have a ton of hosts I want to scan, all with multiple aliases in /etc/hosts. Is there a way to use my current /etc/hosts file to do an ssh-keyscan instead of making a special list of hosts that (from what I've read) ssh-keyscan needs?
View 2 Replies View RelatedI have an init script running as a special build user which performs an automated build that fails with (Too many open files).I updated /etc/security/limits to allow the special user more open files, but that didn't work - the init script still isn't allowed more open files.Here's a demonstration of the problem;
Code:
$ su - sbsbuild -c "ulimit -n"
Password:
[code]....
* Correct me if I am wrong.* In web browser, if I go to a SSL site, I need to install a CA from the SSL site, so the web browser trusts it.* I assume my ubuntu box is working the same way.* That is if I need to do ldap bind or search, I need to install the CA and put it in /etc/ldap/ldap.conf* It works well, if I only have 1 CA in ldap.conf. * If I put 2 CAs in ldap.conf, only the last one will work. e.g.
BASE dc=a,dc=b,dc=c,dc=d
URI ldaps://somesite.com
TLS_REQCERT demand
[code]....
I changed the user name using the User Properties window and rename the home directory with the new user name. Did not change the Group Name. The new name is ResearLab
When I restarted the system I received an error message:
Gnote Crash
gnote 0.7.3-4.fc14
Following are the messages:
(1) could not update ICE authority file/home/ResearLab/.ICE authority
There is a problem with the configuration server
(2) /usr/Libexec/gconf-Sanity-check-2 exited with status 256
(3) Nautilus could not create the following required folders: /home/ResearLab/Desktop, /home/ResearLab/.nautilus.
Before running nautilus, please create these folders or set permission such that natilus can create them.
A. What did I do wrong? Is it not possible to rename a user in Linux?
B. How can I correct this problem?
C. Should I have created a new user instead or renaming an existing one?
D. Can the primary group be renamed?
[URL]
We have the same problem but tried his solution to no avail.
Doing a shh would give me an error..
Quote:
usr/bin/xauth: timeout in locking authority file /var/www/html/felipe/.XauthorityServer sent command exit status 1
When I change SElinux to permissive from enforcing I can login but turning back to enforcing, the problem comes back. I did the following...
Quote:
[felipe@nimitz ~]$ ls -Z .Xauthority
-rw-------. felipe felipe unconfined_ubject_r:httpd_sys_content_t:s0 .Xauthority
[felipe@nimitz ~]$ ls -lZd
drwxr-xr-x. felipe apache system_ubject_r:httpd_sys_content_t:s0 .
[felipe@nimitz ~]$ ps -eZ|grep sshd
[code]....
I tried to create a new user with the default directory in /home and it work fine.
how i can say fedora that if a file has a special suffix to open it with a special app?? such as .oct with octave or ...?
View 6 Replies View Relatedcan get TexLive 2010 for Fedora using a special yum repository at [URL] What yum commands should one use to install it? Does it automatically replace the default Fedora TexLive 2007 installation?
View 13 Replies View RelatedAfter update i cant log into my login account. I cant go into home/mylogin directory.
Unable to read ICE authority file /home/mylogin/.ICEauthority
Do I need to do anything special to my LAMP server for AJAX to work?
View 2 Replies View RelatedI am dragging my files over to a new Fedora 12 installation and I just noticed that special characters are not taken into account when sorting files by name (I want '_js' to come before 'images').Is there a way to make the sorting process behave like Windows, where files starting with a special character are listed first?
View 5 Replies View RelatedI've got my Samba shares up and running. I can stream files from the server, I can create files on the server, and I can copy files from the server.
Running a Windows program (from a Windows box) directly from the Samba server, however, is turning into a nightmare. I'm getting Access is Denied errors from the Windows box, yet I can copy/create/etc from the entire directory with no problems.
Are there any special permissions I need to run EXE files from a Windows box, located on a Samba share? I've already chmod'd everything to 777, and I show full access when ls -Z is used.
I was trying to install freenx on my ubuntu machine and messed up somewhere. Now I cant login to the system. I get these errors Could not update ICEauthority file /home/xbmc/.ICEauthority I tried to login with CTRL-ALT-F2 and putting this command in sudo chown test:test /home/test/.ICEauthority and i get invalid user: 'test:test'
[Code]....
I have installed vnc-server on my CentOS 5.6 virtual machine. I can connect to it with a java web browser so it seems to be working. However, I get the following error message when I start, stop or restart the vnc-server process. Quote: Starting VNC server: 1:ken xauth: timeout in locking authority file /root/.xauthkk661q
View 5 Replies View Relatedlove security/pentest tools. This script adds ALL the tools from the Security Spin, plus Metasploit. Feel free to modify it if need be.
View 12 Replies View Relatedthis is the allert i got:Code:Summary:Your system may be seriously compromised! /usr/sbin/NetworkManager tried to loada kernel module.Detailed Description:SELinux has prevented NetworkManager from loading a kernel module. All confinedprograms that need to load kernel modules should have already had policy writtenfor them. If a compromised application tries to modify the kernel this AVC willbe generated. This is a serious issue.Your system may very well be compromised.Allowing Access:Contact your security administrator and report this issue.Additional Information:
Source Context system_u:system_r:NetworkManager_t:s0
Target Context system_u:system_r:NetworkManager_t:s0
Target Objects None [ capability ]
[code]....
I'm just curious as to what security measure's I should be taking to make my box a little less vulnerable? I'm still experimenting/playing with Linux, use the net, IM, download this and that and was wondering how secure fedora 10 was out of the box?
View 12 Replies View RelatedDuring a recent install I made the leap to encryption,but /boot must remain unencrypted.Is there really any legitimate security risk to having an unencrypted /boot partition? I mean basically someone can just see what kernel you're running which they could see during boot anyways right? Oh I and keep all my financial documents in /boot/finances/ (haha ok not really, but I am serious about the first part).
View 5 Replies View RelatedIs it possible to install security lab menu on a normal Fedora 13 installation? I don't want to use security spin.
View 14 Replies View RelatedIf I leave the computer running for a few minutes without doing anything on it, this screen appears demanding that I enter my password, otherwise I can't get back to Fedora. I understand the necessity for this security feature in a work environment, but I'm just a home user and this security screen is just a nagging problem I don't know how to get rid of.
View 1 Replies View RelatedI just putup the fedora15 on my PC. there are several msg coming up from selinux saying permission denied, though I am not doing any administrative activity. the PC being a workstation for reaserch. how can I know the denial is for an security intrusion attempt. how can I set conditions to see the logs of all security intrusions. how can I set exclusive msg-ing from selinux that the denial is for a security intrusion attempt.
View 5 Replies View RelatedFirefox 3.5 has a critical java script vulnerability as noted in the recent news. I had to manually update to 3.5.1 using the mozilla tarball because there's still no Firefox 3.5.1 in Fedora Updates or even Fedora Updates Testing repositories. Is this normal? I didn't want to resort to using the mozilla one because now I can't use flash (my system is 64 bit and mozilla only seems to offer a 32bit tar file of Firefox) and having two Firefoxs means dealing with the ProfileManager, separate bookmarks and so on.
I'm trying to find out if I'm just looking in the wrong place, I tried the normal mirrors for "updates" for Fedora 11 and then updates-testing and also the baseurl for "updates" to get rid of the mirror update delay. None of them seem to have 3.5.1 ?
Problem that may require several tools available on Fedora. I don't know if its possible or not.
Given: Surveillance video box based on Fedora & Zoneminder. Internet connection is via a private 10.x.x.x network connection to the local phone company/ISP. That's the only connection available and they are the only ISP in the area. The ISP uses NAT to ultimately provide a routeable IP address, but that only works on outbound initiated traffic.
Problem: How can someone out on the Internet hit this box? i.e Is there any way to rig a method that will ultimately allow a connection initiated from the Internet to see the surveillance video that this box has stored via an http session?
I thought of one idea but don't have the tools to implement it. User sends an email to a server out on the Net somewhere. Surveillance box retrieves mail ever minute. The mail contains the users IP address. Surveillance box sends an outbound packet to that IP address to get NAT functional. The users box then uses that address to hit the box on the private network. The snag with this is that NAT is specific to ports, and I have no sway over the ISP's NAT capability.
Is there any way to push an http session outbound to the waiting end user? i.e. initiate a push of http traffic from the private box to the end user?
Does any one knows how to set an schedule for fire fox to terminate loading some IP. or restricting people to accessing some websites from your system..?I mean to set some restriction option to Fire Fox for third party..
View 4 Replies View RelatedI am trying to type German Umlaut letters on an English keyboard using kde 4.4. For some reason I seem unable to figure out how to do that (I have just recently switched to kde, was using gnome before). I have looked through various threads and the kubuntu wiki [URL], but can't get the compose key to work. In gnome I used to type "AltGr" plus "[" followed by a vowel and thus get my Umlaut - before I fiddled with the system settings this worked in kde, but only in firefox & Open Office (I assume they are gtk apps).
Since it did not work in Kmail, I went to the system settings, set up a ComposeKey (AltGr, but also tried rightWin), but it doesn't change anything for the kde applications. It only means that the old key-combination now stopped working in firefox and OO. In the system setting of kde 4.4 I can't see the options to enable xkb-options, but I assume the advanced options of the keyboard layout are xkb-options of previous kde releases. I unticked the box 'reset old options', but nothing changed. I type a lot of German text, so using a character map is not an option.
I've found several how-to's, but the "problem" is that all the ones I've found up to now involve using xmodmap. I'm not radically opposed to that, but, with debian, for some reason, I don't need it. I don't have a Xmodmap file, and yet, the special keys have their "names", instead of NoSymbol (on xev). Anyone knows where the settings are, whenever one does not use xmodmap?To make things weirder I've tried to create a Xmodmap to use with arch from debian, but it get the names all wrong, for some reason. (I used xmodmap -pke > .Xmodmap). I guess that whatever debian does, it has nothing to do with xmodmap then.
But I think it may not be possible. Besides not using xmodmap, on debian I have the correct keyboard layout set without having any command (well, at least not on my openbox startup script... it could be somewhere along all those "deeper" startup scripts, on /etc/rc.#/, I guess... I'm going to check there now), while on arch I have a "setxkbmap" on my openbox startup script.
I wish to make a shortcut which write my name in Thunderbird.Well, my name has an accent in it and I'm really fed up with doing "Insert -> Characters and Symbols" at the end of each of each of my messages, either in my languages or in English.So, I'm looking for a way to write it in just one click or one command.
View 3 Replies View Related