KDE theme wipes user's files using 'rm -rf'

For interesting topics. But remember this is a Linux Forum. Do not post offensive topics that are meant to cause trouble with other members or are derogatory towards people of different genders, race, color, minors (this includes nudity and sex), politics or religion. Let's try to keep peace among the community and for visitors.

No spam on this or any other forums please! If you post advertisements on these forums, your account may be deleted.

Do not copy and paste entire or even up to half of someone else's words or articles into posts. Post only a few sentences or a paragraph and make sure to include a link back to original words or article. Otherwise it's copyright infringement.

You can talk about other distros here, but no MX bashing. You can email the developers of MX if you just want to say you dislike or hate MX.
Message
Author
User avatar
LU344928
Posts: 301
Joined: Wed Nov 14, 2018 11:40 pm

KDE theme wipes user's files using 'rm -rf'

#1 Post by LU344928 »

MX-23 KDE | Devuan Daedalus 5.0 | Slackware 15

User avatar
CharlesV
Global Moderator
Posts: 7092
Joined: Sun Jul 07, 2019 5:11 pm

Re: KDE theme wipes user's files using 'rm -rf'

#2 Post by CharlesV »

Hmm... interesting and scary if that is true / actually what happened.
*QSI = Quick System Info from menu (Copy for Forum)
*MXPI = MX Package Installer
*Please check the solved checkbox on the post that solved it.
*Linux -This is the way!

User avatar
siamhie
Global Moderator
Posts: 3224
Joined: Fri Aug 20, 2021 5:45 pm

Re: KDE theme wipes user's files using 'rm -rf'

#3 Post by siamhie »

CharlesV wrote: Sat Mar 23, 2024 11:23 am Hmm... interesting and scary if that is true / actually what happened.

@CharlesV The user initially posted to r/openSUSE on Reddit and another user posted the (disturbing) code.

Hacked! - Installed a global theme - it erased all my drivers!
https://www.reddit.com/r/openSUSE/comme ... ed_all_my/


user cfeck_kde posted this in response.
I quickly checked its content. It contains, among others, a set of Plasmoids, which are from Plasma 5.

The "plasmaConfSaver" plasmoid contains:

Code: Select all

> cd plasma/plasmoids/com.pajuelo.plasmaConfSaver/contents ; grep -r "rm -Rf" *
scripts/save.sh:rm -Rf "$configFolder"
ui/FullRepresentation.qml:                            if(cmd.indexOf("save.sh") != -1 || cmd.indexOf("rm -Rf") != -1) {
ui/FullRepresentation.qml:                                    executeSource.connectSource("rm -Rf " + savePath + "/" + model.modelData)
It is possible that Plasma 6 tries to execute this script without checking.
This is my Fluxbox . There are many others like it, but this one is mine. My Fluxbox is my best friend. It is my life.
I must master it as I must master my life. Without me, my Fluxbox is useless. Without my Fluxbox, I am useless.

User avatar
CharlesV
Global Moderator
Posts: 7092
Joined: Sun Jul 07, 2019 5:11 pm

Re: KDE theme wipes user's files using 'rm -rf'

#4 Post by CharlesV »

Once again I am reminded of how 'user submissions' can turn bad.

I stopped all Python work because of the high dependency of unknown code libraries, I have always been suspicious of someone else's code over the years. But it was really more due to errors, unstable or just bad programming. But the last x years has shown far more issues that are serious.

This saddens me.
*QSI = Quick System Info from menu (Copy for Forum)
*MXPI = MX Package Installer
*Please check the solved checkbox on the post that solved it.
*Linux -This is the way!

User avatar
davidy
Posts: 818
Joined: Sat Jul 03, 2021 1:59 pm

Re: KDE theme wipes user's files using 'rm -rf'

#5 Post by davidy »

The day ubuntu partnered with canonical was the day I said sayonara. Canonical is the problem and ubuntu the enabler. My favorite recent 'news' is the evga power supply warranty repair process wherein you return your ps sans cables, and then they return the exact same model with different pinouts for the cabling (you kept) with zero notice of the change and absolutely no difference in model# whatsoever. 12V to your HD's is full hardware failure. Lots of predators, incl lazy crappy companies, so stay vigilant and watch out for the wooden nickels. Needless to say evga wanted no part of that and referred the customer to the hd manufacturer instead. Ubuntu because of canonical is dead to me and evga because they prey on "gamers" is as well. Kinda like nvidia's bs.
Sys76 LemurPro-mx-23.4, EliteMinis HM90-mx-21.3, Deskmini UM350-phoenixLite win10, Qnap 12tb nas, Protectli FW4C-opnsense(=゜ω゜)

zero privacy = zero security . All MX'd Up
UAP = up above people

User avatar
asqwerth
Developer
Posts: 7776
Joined: Sun May 27, 2007 5:37 am

Re: KDE theme wipes user's files using 'rm -rf'

#6 Post by asqwerth »

KDE Store issues are separate from Canonical/Ubuntu. It's for Plasma users regardless of distro.
Desktop: Intel i5-4460, 16GB RAM, Intel integrated graphics
Clevo N130WU-based Ultrabook: Intel i7-8550U (Kaby Lake R), 16GB RAM, Intel integrated graphics (UEFI)
ASUS X42D laptop: AMD Phenom II, 6GB RAM, Mobility Radeon HD 5400

User avatar
Stevo
Developer
Posts: 14447
Joined: Fri Dec 15, 2006 7:07 pm

Re: KDE theme wipes user's files using 'rm -rf'

#7 Post by Stevo »

Yes, MX KDE users will also be vulnerable.
MXPI = MX Package Installer
QSI = Quick System Info from menu
The MX Test repository is mostly backports; not the same as Debian testing

User avatar
davidy
Posts: 818
Joined: Sat Jul 03, 2021 1:59 pm

Re: KDE theme wipes user's files using 'rm -rf'

#8 Post by davidy »

Your right. Apparently with kde themes they are allowed to run any kind of script which in and of itself is what makes kde so magical and bloaty all at the same time. Sorry about the canonical rant. I was referring to some crypto wallet scammers which are being uploaded and when they are taken down the scammers just create a new acct and re-upload them. Thanks for the clarification. So you have a choice of your data wiped, your hd's controller's destroyed potentially losing all your data if not fixed, and all your crypto stolen. I think my favorite is the roku tv's which deactivate when you don't agree.
Fun fact. If you watch tubi on a roku whenever there is a commercial just keep hitting the back button, and then resume, until the movie plays again. It works
Sys76 LemurPro-mx-23.4, EliteMinis HM90-mx-21.3, Deskmini UM350-phoenixLite win10, Qnap 12tb nas, Protectli FW4C-opnsense(=゜ω゜)

zero privacy = zero security . All MX'd Up
UAP = up above people

User avatar
sunrat
Posts: 663
Joined: Mon Mar 28, 2016 9:54 pm

Re: KDE theme wipes user's files using 'rm -rf'

#9 Post by sunrat »

If that happens, one should just restore the system backup they made before installing potentially damaging software! ;)
Everyone makes backups, don't they?

User avatar
Mauser
Posts: 1440
Joined: Mon Jun 27, 2016 7:32 pm

Re: KDE theme wipes user's files using 'rm -rf'

#10 Post by Mauser »

Ouch! :eek: This reminds me of Snaps. 9_9 Seems like KDE is not secure if this can happen. This is one thing I find very disturbing in the Linux community. Some don't secure their repositories and or websites then always push the blame onto the end-user that they should have back ups when they are the guilty party due to their gross incompetence. :rolleyes: When someone points out their goof-ups those people get attack when they are the one to blame. :mad: Linux is suppose to be safe and secure but theses idiots are doing a great disservice to the Linux brand. :frown: All software must be checked and vetted before it's put on the Internet and no excuses are acceptable. This is one of the many reasons why I have two backups of my files because we have idiots like these that are too lazy to check everything uploaded to their site. :mad:
I am command line illiterate. :confused: I copy & paste to the terminal. Liars, Wiseguys, Trolls, and those without manners will be added to my ignore list. :mad:

Post Reply

Return to “General”