home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sgi
- Path: sparky!uunet!utcsri!skule.ecf!epas!adam
- From: adam@epas.utoronto.ca (Adam Iles)
- Subject: Re: shutdown by user
- Organization: University of Toronto - EPAS
- Date: Mon, 17 Aug 1992 19:54:29 GMT
- Message-ID: <1992Aug17.195429.2312@epas.toronto.edu>
- References: <o6a8rsk@zuni.esd.sgi.com> <1992Aug13.180112.2505@ctr.com> <ojsf4ek@rhyolite.wpd.sgi.com>
- Sender: news@epas.toronto.edu (USENET)
- Nntp-Posting-Host: epas.utoronto.ca
- Lines: 15
-
- In article <ojsf4ek@rhyolite.wpd.sgi.com> vjs@rhyolite.wpd.sgi.com (Vernon Schryver) writes:
- >True, but that hole does not exist if you use a line like
- >
- >shutdown:asdfasdf:0:0:shutdown:/:/etc/halt
-
- You may want to make sure that you add shutdown to your /etc/ftpusers
- file! If you let a person ftp as root there is no reason why he would
- not be able to just upload a new /etc/passwd file, or am I missing some
- basic piece of security that has already been discussed?
-
- Never trust anyone to have addressed ALL of the security issues.
- --
- Adam Iles Fractals:
- EPAS Computing, University of Toronto The tie-dye of the 90's
- adam@epas.utoronto.ca
-