home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!mcsun!uknet!warwick!dcs.warwick.ac.uk!sunserver1.aston.ac.uk!uhura!evansmp
- From: evansmp@uhura.aston.ac.uk (Mark Evans)
- Newsgroups: comp.security.misc
- Subject: Re: root-owned world-writable files
- Message-ID: <1992Jul23.214456.17288@aston.ac.uk>
- Date: 23 Jul 92 21:44:56 GMT
- References: <1992Jul23.114717.29349@jarvis.csri.toronto.edu>
- Sender: usenet@aston.ac.uk (Usenet administrator)
- Organization: Aston University
- Lines: 17
- Nntp-Posting-Host: uhura
-
- flaps@dgp.toronto.edu (Alan J Rosenthal) writes:
- : But anyway, it's an extremely serious security hole to have "/" be world-
- : writable. The /.rhosts problem is a negligible portion of this problem.
- : Just rename /etc and the system will let you login to root without asking
- : for a password anyway.
- This sounds like the same sort of philophicy used in VAX/VMS if it can't find
- SYS$UAF (the equivalent of /etc/password)
- It gives you all privs.
- I think the assumption (on the part of the OS) is that the file system
- is trashed and you need the privs to fix it.
- (though I have a feeling that VMS will only allow a console login in
- that situation)
- --
- -------------------------------------------------------------------------
- Mark Evans |evansmp@uhura.aston.ac.uk
- +(44) 21 565 1979 (Home) |evansmp@cs.aston.ac.uk
- +(44) 21 359 6531 x4039 (Office) |
-