Re: "passwd -F" vulnerability?

Steve Simmons (scs@lokkur.dexter.mi.us)
Wed, 11 May 1994 07:29:05 -0400 (EDT)

Pat Myrto wrote:

>   So what?  One can copy /etc/passwd and edit it with an EDITOR.  So?
>   Login reads /etc/passwd, not whatever file the user chooses. . . .
>   Its not a problem.

Do

	passwd -F /etc/shadow

Now the shadow password file is visible in /var/adm/messages.