home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!haven.umd.edu!darwin.sura.net!zaphod.mps.ohio-state.edu!sol.ctr.columbia.edu!usc!news.service.uci.edu!draco.acs.uci.edu!iglesias
- From: iglesias@draco.acs.uci.edu (Mike Iglesias)
- Subject: Re: user operator has uid 0 and not root.
- Nntp-Posting-Host: draco.acs.uci.edu
- Message-ID: <2AB54C6E.12682@news.service.uci.edu>
- Newsgroups: comp.unix.ultrix
- Organization: University of California, Irvine
- Lines: 38
- Date: 15 Sep 92 02:37:34 GMT
- References: <1992Sep14.101106.1@vax.sonoma.edu>
-
- In article <1992Sep14.101106.1@vax.sonoma.edu> mccalld@vax.sonoma.edu writes:
- >Greetings:
- > I'm working from a COPS report which says Warning! Password
- >file, line 56, user operator has uid = 0 and is not root.........
- >Now, I am trying to make it so that user operator can only login from
- >the system console (ie secure defined port), and doesn't need a
- >password, and is put into SCAMP directly upon login
-
- I don't know about anyone else, but I would *NEVER* have a uid 0 login
- with no password on any of my systems, no matter how secure they may
- be. If SCAMP needs to be run as uid 0, you really need a password
- on that account.
-
- >.....I have modified
- >SCAMP so that the exit to system selection on the main menu is now
- >a loggout option, thus the operator can never get into the system
-
- I'm not familiar with SCAMP, but are you absolutely positively sure that
- there are no shell escapes and/or ways to run arbitrary programs in any
- program that SCAMP runs? If there are, your operators can get into the
- system with little trouble.
-
- >I'd really like COPS to run without errors....
-
- I think COPS will notice your uid 0 login with no password, so you may
- want to rethink how your are doing this. In fact, I think it complains
- about any account with no password.
-
- If you're interested in the security of your system, you might want to
- pick up a copy of "Practical Unix Security" by Spafford and Garfinkel,
- published by O'Reilly & Associates.
-
-
- Mike Iglesias Internet: iglesias@draco.acs.uci.edu
- University of California, Irvine BITNET: iglesias@uci
- Office of Academic Computing uucp: ...!ucbvax!ucivax!iglesias
- Distributed Computing Support phone: (714) 856-6926
-
-