Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Unable to su on firewall

From: Matt Collins <matt(at)clues.com>
Date: Tue Apr 22 2003 - 09:05:17 EDT

On Wed, Apr 16, 2003 at 06:55:45PM +0200, Daniel Bergman wrote:
> Hi,
>
> I'm having huge problems switching user, using su utility, to a user named 'daniel' on my Solaris 8 x86 server.

While not directly related to your query, given this is a security based list....

Change daniel's password as you've included the crypt string and never set folks home dirs to /tmp - its a world writable directory and to compromise your machine its just a matter of getting a substitute .profile, .login, .forward, etc in there. Once a file that will be executed on system events (receipt of mail, login, etc) is created its just a matter of time before it gets executed. This allows any access to the firewall, even 'nobody' or other production 'unprivileged' accounts to start executing with user privs.

If you already knew all that, sorry ;) Dont suppose it hurts to reiterate though.

As for the chdir... what are the permissions on "/", the root directory?

> 739: setuid(3333) = 0
> 739: chdir("/tmp") Err#13 EACCES <-- Really strange, see below for /tmp listing.

Matt Received on Tue Apr 22 10:30:13 2003

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:37 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library