ubuntu-bug linux, lucid install security issue (ubuntu-user modified dvd)

Bug #691476 reported by peter massen
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Ubuntu
Invalid
Undecided
Unassigned

Bug Description

I have installed lucid 10.04 from DVD (ubuntu-user mag issue 6) which installs google picasa and oracle virtual-box by default. A folder in /home appears with name "tommy" along with my <user> folder, permissions are owned by root, tommy contains a folder .google , I have MASSIVE concerns, given the root permissions, over the security implications.

I have done two installs - both with same result.

Based on the information below I am thinking its gota be something to do with oracles virtual box - but the security aspect worries me greatly as given the permissions it probably runs as root.

grep tommy /etc/passwd seems to produce no output at all so tommy does not appear to be a user

also inside folder tommy are files: .bash_history .esd_auth .pulse-cookie , all of which are locked (root only) as well as .google

The contents of .bash_history after install are as follows:

mkldir packs
mkdir packs
cd packs/
ls
gdebi google-chrome-stable_current_i386.deb
ll
ll
ls -ali
gdebi picasa_3.0-current_i386.deb
ls
gdebi skype-ubuntu-intrepid_2.1.0.81-1_i386.deb
ls
ls -ali
gdebi teamviewer_linux.deb
gdebi teamviewer_linux.deb
ls
rm uck_2.*
ls
./truecrypt-6.3a-setup-x86
truecrypt
pwd
ls
picasa
cd packs/
ls
gedit /etc/apt/sources.list
apt-get update
wget -q http://download.virtualbox.org/virtualbox/debian/oracle_vbox.asc -O- | sudo apt-key add -
apt-get update
sudo wget --output-document=/etc/apt/sources.list.d/medibuntu.list http://www.medibuntu.org/sources.list.d/$(lsb_release -cs).list && sudo apt-get --quiet update && sudo apt-get --yes --quiet --allow-unauthenticated install medibuntu-keyring && sudo apt-get --quiet update
gedit /etc/apt/sources.list
synaptic
apt-get install virtualbox 3.2
apt-get install VirtualBox 3.2
apt-get update
apt-get install sun-java-
apt-get install sun-java
exit
gedit /etc/apt/sources.list
gedit /etc/apt/sources.list
apt-get install virtualbox-3.2
wget -q http://download.virtualbox.org/virtualbox/debian/oracle_vbox.asc -O- | sudo apt-key add -
gedit /etc/apt/sources.list
apt-get update
apt-get install virtualbox-3.2
add-apt-repository "deb http://archive.canonical.com/ lucid partner"
apt-get update
synaptic
synaptic
ls
cd packs/
ls
ls
gdebi virtualbox-3.2_3.2.6-63112~Ubuntu~lucid_i386.deb
ps -ax
gdebi virtualbox-3.2_3.2.6-63112~Ubuntu~lucid_i386.deb
exit

Please ask if further details needed - Thankyou

Revision history for this message
Fabio Marconi (fabiomarconi) wrote :

Thank you for taking the time to report this bug and trying to help make Ubuntu better. However, it seems that you are not using a software package provided by the official Ubuntu repositories. Because of this the Ubuntu project can not support or fix your particular bug. Please report this bug to the provider of the software package. Thanks!

summary: - ubuntu-bug linux, lucid install security issue
+ ubuntu-bug linux, lucid install security issue (ubuntu-user modified
+ dvd)
Changed in ubuntu:
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Related questions

Remote bug watches

Bug watches keep track of this bug in other bug trackers.