|
|||||||||||
|
Re: Unable to su on firewall
From: Matt Collins <matt(at)clues.com>
Date: Tue Apr 22 2003 - 09:05:17 EDT
On Wed, Apr 16, 2003 at 06:55:45PM +0200, Daniel Bergman wrote:
While not directly related to your query, given this is a security based list.... Change daniel's password as you've included the crypt string and never set folks home dirs to /tmp - its a world writable directory and to compromise your machine its just a matter of getting a substitute .profile, .login, .forward, etc in there. Once a file that will be executed on system events (receipt of mail, login, etc) is created its just a matter of time before it gets executed. This allows any access to the firewall, even 'nobody' or other production 'unprivileged' accounts to start executing with user privs. If you already knew all that, sorry ;) Dont suppose it hurts to reiterate though. As for the chdir... what are the permissions on "/", the root directory? > 739: setuid(3333) = 0
Matt Received on Tue Apr 22 10:30:13 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:37 EDT |
||||||||||
|
|||||||||||