home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sgi
- Path: sparky!uunet!elroy.jpl.nasa.gov!ames!sgi!rhyolite!vjs
- From: vjs@rhyolite.wpd.sgi.com (Vernon Schryver)
- Subject: Re: shutdown by user
- Message-ID: <on7kv68@rhyolite.wpd.sgi.com>
- Organization: Silicon Graphics, Inc. Mountain View, CA
- References: <o6a8rsk@zuni.esd.sgi.com> <1992Aug13.180112.2505@ctr.com> <1992Aug17.195429.2312@epas.toronto.edu>
- Date: Tue, 18 Aug 1992 04:04:14 GMT
- Lines: 26
-
- In article <1992Aug17.195429.2312@epas.toronto.edu>, adam@epas.utoronto.ca (Adam Iles) writes:
- > In article <ojsf4ek@rhyolite.wpd.sgi.com> vjs@rhyolite.wpd.sgi.com (Vernon Schryver) writes:
- > >True, but that hole does not exist if you use a line like
- > >
- > >shutdown:asdfasdf:0:0:shutdown:/:/etc/halt
- >
- > You may want to make sure that you add shutdown to your /etc/ftpusers
- > file! If you let a person ftp as root there is no reason why he would
- > not be able to just upload a new /etc/passwd file, or am I missing some
- > basic piece of security that has already been discussed?
- >
- > Never trust anyone to have addressed ALL of the security issues.
-
-
- How is this "shutdown" entry any more or less of a security hole
- for ftp than the "root" entry in /etc/passwd?
-
- If you can use FTP and "shutdown" to change /etc/passwd without knowing
- the right password, then you can use FTP and "root" without knowning
- the password.
-
- In other words, I do not think this line creates any additional
- security holes.
-
-
- Vernon Schryver, vjs@sgi.com
-