home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!dtix!oasys!hendrix
- From: hendrix@oasys.dt.navy.mil (Dane Hendrix)
- Newsgroups: comp.sys.sgi
- Subject: Re: shutdown by user
- Message-ID: <23754@oasys.dt.navy.mil>
- Date: 18 Aug 92 11:22:16 GMT
- References: <o6a8rsk@zuni.esd.sgi.com> <on7kv68@rhyolite.wpd.sgi.com>
- Reply-To: hendrix@oasys.dt.navy.mil (Dane Hendrix)
- Organization: Code 1542, DTMB, Bethesda, MD
- Lines: 37
-
- In comp.sys.sgi, vjs@rhyolite.wpd.sgi.com (Vernon Schryver) writes:
- |In article <1992Aug17.195429.2312@epas.toronto.edu>, adam@epas.utoronto.ca (Ada
- |m Iles) writes:
- |> In article <ojsf4ek@rhyolite.wpd.sgi.com> vjs@rhyolite.wpd.sgi.com (Vernon Sc
- |hryver) writes:
- |> >True, but that hole does not exist if you use a line like
- |> >
- |> >shutdown:asdfasdf:0:0:shutdown:/:/etc/halt
- |>
- |> You may want to make sure that you add shutdown to your /etc/ftpusers
- |> file! If you let a person ftp as root there is no reason why he would
- |> not be able to just upload a new /etc/passwd file, or am I missing some
- |> basic piece of security that has already been discussed?
- |>
- |> Never trust anyone to have addressed ALL of the security issues.
- |
- |How is this "shutdown" entry any more or less of a security hole
- |for ftp than the "root" entry in /etc/passwd?
- |
- |If you can use FTP and "shutdown" to change /etc/passwd without knowing
- |the right password, then you can use FTP and "root" without knowning
- |the password.
- |
- |In other words, I do not think this line creates any additional
- |security holes.
-
- I agree with the need for an /etc/ftpusers entry. The reason for having
- a shutdown account was so that a less closely held password could
- enable users to shutdown the system. If there is no entry in the
- /etc/ftpusers file for the shutdown account, the damage possible due
- to disclosure of the shutdown password is nearly(?) as great as that
- due to disclosure of the root password.
-
- Dane Hendrix | email: dane@wizard.dt.navy.mil
- DTMB (a.k.a. Headquarters, Carderock Div.,| or hendrix@oasys.dt.navy.mil
- Naval Surface Warfare Center) | or hendrix@nas.nasa.gov
- Code 1542, Bethesda, MD 20084-5000 | phone: (301)227-1340
-