Re: Environment Poisoning and login -p

From: Mike Hoskins (mike_at_adept.org)
Date: 02/27/04

  • Next message: Andrew McNaughton: "Re: Environment Poisoning and login -p"
    Date: Fri, 27 Feb 2004 11:43:50 -0800 (PST)
    To: freebsd-security@FreeBSD.ORG
    
    

    On Fri, 27 Feb 2004, Dag-Erling [iso-8859-1] Smørgrav wrote:
    > Agreed, let's let this discussion die instead. login(1) is no longer
    > setuid root, so the whole thing is a non-issue.

    to be complete, i assume you mean under 5.x:

    mike@snafu{mike}$ uname -r
    4.8-RELEASE-p15
    mike@snafu{mike}$ ls -al /usr/bin/login
    -r-sr-xr-x 1 root wheel 21824 Feb 23 13:45 /usr/bin/login*

    hard to believe, but not everyone is using 5.x. ;) still, since 5.x is
    stable and fast (...er than 4.x in many ways), i agree making extra work
    in the name of 4.x is probably not the best idea when development
    resources are already scare.

    (of course if someone is paranoid and wants to make relevant patches
    against 4.x, and maintain them seperately, i'm sure at least some people
    wouldn't object.)

    -m
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Andrew McNaughton: "Re: Environment Poisoning and login -p"

    Relevant Pages

    • Re: print or die
      ... If you want to make highly robust programs, ... make the effort to make them highly robust. ... So if you are really paranoid (and ... Actually, I generally start it with 'or die', then kick myself for not ...
      (comp.lang.perl.misc)
    • Re: Action Comics Annual #10: And The Fun Just Wont Stop!
      ... You've posted some variation on this something like six or seven times ... As it happens, you called _yourself_ paranoid. ... comics she was sure to die just as soon as I stopped writing her, ... like the still-not-dead Linda Park was sure to die as soon as Mark Waid ...
      (rec.arts.comics.dc.universe)
    • Re: Environment Poisoning and login -p
      ... > Whoa, Let's not complicate things unnecessarily. ... let's let this discussion die instead. ... setuid root, so the whole thing is a non-issue. ...
      (FreeBSD-Security)
    • Re: Lee Jones and others: Your opinion please (long)
      ... >>> First time I ever played at a table with you you told me that you hoped I ... >>> would die, because I took a pot off you. ... >Whatever greivous injury I caused you, maybe it's time to let it go. ... just because you're paranoid doesn't mean their NOT out to ...
      (rec.gambling.poker)
    • Re: another newpaper report.....
      ... Just because I have a different opinion to you does not mean I am menally ill. ... you just fuck off and die somewhere. ... *paranoid* /adj./ Exhibiting or characterized by extreme and irrational ...
      (uk.rec.cycling)