ubuntu-bug linux, lucid install security issue (ubuntu-user modified dvd)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu |
Invalid
|
Undecided
|
Unassigned |
Bug Description
I have installed lucid 10.04 from DVD (ubuntu-user mag issue 6) which installs google picasa and oracle virtual-box by default. A folder in /home appears with name "tommy" along with my <user> folder, permissions are owned by root, tommy contains a folder .google , I have MASSIVE concerns, given the root permissions, over the security implications.
I have done two installs - both with same result.
Based on the information below I am thinking its gota be something to do with oracles virtual box - but the security aspect worries me greatly as given the permissions it probably runs as root.
grep tommy /etc/passwd seems to produce no output at all so tommy does not appear to be a user
also inside folder tommy are files: .bash_history .esd_auth .pulse-cookie , all of which are locked (root only) as well as .google
The contents of .bash_history after install are as follows:
mkldir packs
mkdir packs
cd packs/
ls
gdebi google-
ll
ll
ls -ali
gdebi picasa_
ls
gdebi skype-ubuntu-
ls
ls -ali
gdebi teamviewer_
gdebi teamviewer_
ls
rm uck_2.*
ls
./truecrypt-
truecrypt
pwd
ls
picasa
cd packs/
ls
gedit /etc/apt/
apt-get update
wget -q http://
apt-get update
sudo wget --output-
gedit /etc/apt/
synaptic
apt-get install virtualbox 3.2
apt-get install VirtualBox 3.2
apt-get update
apt-get install sun-java-
apt-get install sun-java
exit
gedit /etc/apt/
gedit /etc/apt/
apt-get install virtualbox-3.2
wget -q http://
gedit /etc/apt/
apt-get update
apt-get install virtualbox-3.2
add-apt-repository "deb http://
apt-get update
synaptic
synaptic
ls
cd packs/
ls
ls
gdebi virtualbox-
ps -ax
gdebi virtualbox-
exit
Please ask if further details needed - Thankyou
Thank you for taking the time to report this bug and trying to help make Ubuntu better. However, it seems that you are not using a software package provided by the official Ubuntu repositories. Because of this the Ubuntu project can not support or fix your particular bug. Please report this bug to the provider of the software package. Thanks!