Re: why is the nobody account password-protected?

From: Bill Unruh (unruh_at_string.physics.ubc.ca)
Date: 07/22/04

  • Next message: Lew Pitcher: "OT: Bill, was that you in the Thursday Toronto Star?"
    Date: 22 Jul 2004 21:02:17 GMT
    
    

    Kevin Rodgers <ihs_4664@yahoo.com> writes:

    ]On Solaris and GNU/Linux at least, the nobody account has a single
    ]character password -- why? I think it'd make sense to allow any user
    ]to `su nobody` to safely run risky commands without any priveleges.

    A sinle letter either means the password is in /etc/shadow, or noone is
    allowed to use that account. It is for use onlyby root.
    I think it would be a bad idea to let others use it.
    Any user without a password is a HUGE security risk. Youmay assume that a
    cracker wh signs on that user will have root. I do not care what the
    priviledge level of hte account is.


  • Next message: Lew Pitcher: "OT: Bill, was that you in the Thursday Toronto Star?"

    Relevant Pages

    • Re: Compromise of the nobody account?
      ... Unix-like system, and said account has been broken into and is being ...  What can you do as 'nobody' without a shell? ... So then I take that it's NOT a good idea to have a nobody account ...
      (comp.security.unix)
    • Re: Compromise of the nobody account?
      ... Unix-like system, and said account has been broken into and is being ...  What can you do as 'nobody' without a shell? ... So then I take that it's NOT a good idea to have a nobody account ...
      (comp.security.unix)
    • Re: Can you delete the Administrator account?
      ... you can't delete the administrator ... main user account not to be an administrator. ... character password, they're going to be surprised to find ... >Administrator folders ...
      (microsoft.public.win2000.general)
    • Re: SQL 2005 Upgrade Error Password
      ... I changed the SA to a 12 character password and the error still occurs. ... have no idea what account it could be referring. ... Prev by Date: ...
      (microsoft.public.sqlserver.setup)

  • Quantcast