home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!mcsun!uknet!warwick!dcs.warwick.ac.uk!sunserver1.aston.ac.uk!uhura!evansmp
- From: evansmp@uhura.aston.ac.uk (Mark Evans)
- Newsgroups: comp.security.misc
- Subject: Re: root-owned world-writable files
- Message-ID: <1992Jul23.184638.16460@aston.ac.uk>
- Date: 23 Jul 92 18:46:38 GMT
- References: <1992Jul23.011952.26697@lut.ac.uk>
- Sender: usenet@aston.ac.uk (Usenet administrator)
- Organization: Aston University
- Lines: 15
- Nntp-Posting-Host: uhura
-
- jon_care@hicom.lut.ac.uk writes:
- : An exception occurs to me in the case of /etc/utmp under SunOS 4.1.1 - the mode
- : this is set to by default is 666, hence it is world writeable.
- : If you reedit this with a simple C Program, you can make yourself invisible to
- : who commands etc. and also can evade certain accounting programs.
- Also programs running in windows don't exit correctly then utmp is not tidyed
- up, resulting in people appearing to still be on.
- Also it makes it possible to completly fake who is actually using the machine
- running finger to check who is on a SunOS machine is a complete waste of time.
- :
- --
- -------------------------------------------------------------------------
- Mark Evans |evansmp@uhura.aston.ac.uk
- +(44) 21 565 1979 (Home) |evansmp@cs.aston.ac.uk
- +(44) 21 359 6531 x4039 (Office) |
-