special files as .plans?

Dan Bernstein brnstnd at kramden.acf.nyu.edu
Tue Aug 28 03:15:56 AEST 1990


In article <7391 at star.cs.vu.nl> maart at cs.vu.nl (Maarten Litmaath) writes:
> The real bug is fingerd running as
> root: root can open any (local) file...  (Think about it!)

Of course, this is only a problem when the cracker has a local account.

This is one reason why fingerd runs as ``nobody'' (or a similarly
restricted user) under current systems. The servers provided with
authutil do this correctly.

---Dan



More information about the Comp.unix.wizards mailing list