Shaman doesn't ask for root password. But gets root privileges!!

As the title says:
Shaman is launched as a reguler user, never asks for root password, but still i able to install and uninstall packages.
Either something in my system is seriously fucked, or there is a major securiy problem with shaman.
Running openbox, installed shaman while running gnome, if that has anythiung to say. Sudo is not installed.
Output from running shaman in terminal:
[gert@flyktig ~]$ shaman
This process is currently running setuid or setgid.
GTK+ does not allow this therefore Qt cannot use the GTK+ integration.
Try launching your app using 'gksudo', 'kdesudo' or a similar tool.
See http://www.gtk.org/setuid.html for more information.
Translations are enabled.
Loading translations from "/usr/share/shaman/translations/"
Parsing "core"
Parser exited
Parsing "extra"
Parser exited
Parsing "community"
Parser exited
Parser exited
Log File should be: ""
"core" ---> "http://mirror.archlinux.no/core/os/i686"
"extra" ---> "http://mirror.archlinux.no/extra/os/i686"
"community" ---> "http://mirror.archlinux.no/community/os/i686"
Root privileges retired.
"/home/gert/.config/shaman/shaman.conf"
>>
>> Shaman 1.0.9
>> Compiled against Qt 4.4.1
>> Running with Qt 4.4.3
>>
>> Our website is @ http://shaman.iskrembilen.com/ , join in!!
>> You can also find a bugtracker in the website, please use it.
>>
>> Have you found a bug? Help us solving it faster! Please read
>> http://shaman.iskrembilen.com/trac/wiki/Debugging_Shaman
>> and please follow these steps to report bugs effectively!
>>
>> Starting Up Shaman...
User agent is: "shaman/1.0.9 (Linux i686) libalpm/3.1.1"
Shaman registered on the System Bus as ":1.51"
Service org.archlinux.shaman successfully exported on the System Bus.
--> UNSETENV HTTP_PROXY
--> UNSETENV FTP_PROXY
Populating Repo column
Log file is: /var/log/pacman.log
refinePkgView
The left TextBox is over, let's do the ComboBox
Show all packages
Remove Package
"Uninstall package: alunn"
"alunn"
"community"
Process Queue
Queue Dialog started
Queue signals connected
Starting Package Removal
Root Privileges granted.
Uid is: 1000
Received Event Callback
Alpm Thread Waiting.
Entering Queue Lock
Releasing Queue Lock
Alpm Thread awake.
Received Event Callback
Alpm Thread Waiting.
Entering Queue Lock
Releasing Queue Lock
Alpm Thread awake.
Received Event Callback
Alpm Thread Waiting.
Entering Queue Lock
No scriptlet for package alunn
Releasing Queue Lock
Alpm Thread awake.
Received Event Callback
Alpm Thread Waiting.
Entering Queue Lock
No scriptlet for package alunn
Releasing Queue Lock
Alpm Thread awake.
/sbin/ldconfig: Can't create temporary cache file /etc/ld.so.cache~: Ikke tilgang
Root privileges retired.
Transaction Completed Successfully
refinePkgView
refinePkgView
The left TextBox is over, let's do the ComboBox
Show all packages
[gert@flyktig ~]$

The point of this thread was that you don't need to enter the root password at all. Not the first time, not ever.
As far as I understand, it is supposed to work like this: When you first use shaman too install anything, it asks for the root password You can tick a "Do not ask me again"-box, so you don't have to enter the password again. If you tick the box and enter the password, shaman add the lines
[auth]
askforpwd=false
to the users shaman.conf-file (~./config/shaman/shaman.conf) The next time shaman is run, it checks the config file, and if the askforpwd value is set to false, it grants itself root privileges (with some nifty setuuid root-thingy, I imagine) This is not the problem - this is the feature.
The bug is this:
the fact that any user can add the lines
[auth]
askforpwd=false
to his own shaman.conf file, without ever entering the root password in shaman. The next time shaman is run, it checks the config file, and if the askforpwd value is set to false, it grants itself root privileges - even though the user has never entered the root password.
This works for any unprivileged user on the system.
If that is indeed a feature intended by any sane person, then I'm Mother Mary. And that can't be, seeing as I don't have breasts.

Similar Messages

Maybe you are looking for

  • Jdev 10.1.2  JBO-33001: Cannot find the configuration file bc4j.xcfg in cla

    Hi all, i have a ear application containing a web app and a bc4j module deployed on the embedded oc4j instance inside JDeveloper 10.1.2 (build 1929). Inside the model i have a topic durable subscriber that, when a message is sent, invoke, by reflecti

  • Weird problems of figures with word to pdf conversion

    Platform: Windows Vista Word 2007 Acrobat 9 Q: I have some wmf format vector figures inserted into word file. When I convert the word file into pdf format using the built-in pdfmaker button in the word menu, the vector graphics all become bitmap type

  • 5.1 Out

    I did some searches, and found the question asked before, but no answers. The posts are quite old though, so I thought I'd ask again and see if anyone has anything new. I've got an Audigy 2 with a digital output to the Creative DDTS-00 decoder, then

  • ITunes constantly crashing

    Everytime I start iTunes, I get the spinning candy wheel of death after a couple of minutes - even when nothing is synching and it's not even playing music. I can't delete it and reinstall it. What can I do?

  • Embedded Image(s) not displaying (CRXI,  java)

    Post Author: ph03nix CA Forum: General I've embedded a company logo into the header (subreport) for some reports.  These display locally and on the Business Objects server, but we're getting a broken image when we call the report from the application