From owner-freebsd-questions@FreeBSD.ORG Sat Nov 8 17:23:27 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id ACBA516A4CE for ; Sat, 8 Nov 2003 17:23:27 -0800 (PST) Received: from gaultopia.org (yttrium.4ph.com [66.197.0.170]) by mx1.FreeBSD.org (Postfix) with ESMTP id 87D3D43FBD for ; Sat, 8 Nov 2003 17:23:26 -0800 (PST) (envelope-from krs@gaultopia.org) Received: (qmail 1277 invoked by uid 1009); 9 Nov 2003 01:23:25 -0000 Date: Sat, 8 Nov 2003 20:23:25 -0500 From: kirt To: freebsd-questions@freebsd.org Message-ID: <20031109012325.GD829@yttrium.gaultopia.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.5.4i Subject: vulnerability in su? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 09 Nov 2003 01:23:27 -0000 while recently cvsup'ing my box here at home, i had a weird thing happen... i had already built world, built and installed the kernel, installed world (including all appropriate reboots), and when i brought it back up, but prior to running mergemaster, i popped the jumper on the circuit the box is on. my ups is somewhat wimpy, and only lasts a couple minutes (the fuse trips all the time too.. stupid apartment wiring can't handle 2 computers and the washer and dryer at once =P ) so i made it a priority to go ahead and shut the box down. after fixing said jumper and bring the box back up i noticed that i could now su like a madman, without ever being prompted for passwords. i then remembered that i hadn't run mergemaster yet, so i ran it again and rebooted for safe measure and su started asking for passwords again. is this a known issue? i didn't search to hard for a fix or anything since i quickly fixed it myself, but i thought that a situation like that could make for some interesting (read *bad*) situations. -kirt