From owner-freebsd-current@FreeBSD.ORG Thu Nov 13 06:17:48 2003 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 7729E16A4CE for ; Thu, 13 Nov 2003 06:17:48 -0800 (PST) Received: from ion.gank.org (ion.gank.org [69.55.238.164]) by mx1.FreeBSD.org (Postfix) with ESMTP id A41B543FB1 for ; Thu, 13 Nov 2003 06:17:47 -0800 (PST) (envelope-from craig@xfoil.gank.org) Received: from localhost (ion.gank.org [69.55.238.164]) by ion.gank.org (GankMail) with ESMTP id 0ED6E2B861; Thu, 13 Nov 2003 08:17:47 -0600 (CST) Received: from ion.gank.org ([69.55.238.164]) by localhost (ion.gank.org [69.55.238.164]) (amavisd-new, port 10024) with LMTP id 99758-08; Thu, 13 Nov 2003 08:17:46 -0600 (CST) Received: from owen1492.uf.corelab.com (pix.corelab.com [12.45.169.2]) by ion.gank.org (GankMail) with ESMTP id 634682B7A9; Thu, 13 Nov 2003 08:17:45 -0600 (CST) From: Craig Boston To: Terry Lambert Date: Thu, 13 Nov 2003 08:17:41 -0600 User-Agent: KMail/1.5.4 References: <20031112091032.GA4425@cactus> <3FB3758A.9B52625D@mindspring.com> In-Reply-To: <3FB3758A.9B52625D@mindspring.com> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200311130817.41809.craig@xfoil.gank.org> X-Virus-Scanned: by amavisd-new at gank.org cc: current@freebsd.org Subject: Re: xscreensaver bug? X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 13 Nov 2003 14:17:48 -0000 > Absolutely worst case, the root user could log in remotely, gdb > your screen saver, type "foobar" as the password, and then hack > the authentication function return value to say "yes, that's the > correct password for "jqdkf@army.com", and get in without needing > to have xscreensaver accept the root password. Or, even easier, log in remotely as root and simply "killall -9 xscreensaver". I've had to do that a few times myself when I first tried out pam_krb5 and learned the hard way that xscreensaver doesn't like it very much (and my user account has * in the local password field). Craig