Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 15 Sep 2000 12:17:35 +0200
From:      sthaug@nethelp.no
To:        andys@telinco.net
Cc:        nbm@mithrandr.moria.org, mike@mikesweb.com, freebsd-isp@FreeBSD.ORG
Subject:   Re: one more for ya..
Message-ID:  <7413.969013055@verdi.nethelp.no>
In-Reply-To: Your message of "Fri, 15 Sep 2000 11:07:54 %2B0100 (BST)"
References:  <Pine.BSF.4.10.10009151105460.45019-100000@internal.mail.telinco.net>

next in thread | previous in thread | raw e-mail | index | archive | help
> > > -r-sr-xr-x    1 root   wheel     19556 Jul 30 00:49 /usr/bin/login
> > 
> > Not incredibly sure about this requirement.
> 
> Wouldn't this be needed to read the encrypted passwords from /etc/master.passwd?

/usr/bin/login *only* needs to be setuid root to allow a direct "login"
from one user to another. Under normal circumstances /usr/bin/login is
called from a program already running as root (e.g. telnetd) and thus
doesn't need to be setuid.

Steinar Haug, Nethelp consulting, sthaug@nethelp.no


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?7413.969013055>