Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 19 May 2003 05:19:24 -0700
From:      Kris Kennaway <kris@obsecurity.org>
To:        Frank Bonnet <bonnetf@bart.esiee.fr>
Cc:        freebsd-current@freebsd.org
Subject:   Re: "su" bug
Message-ID:  <20030519121923.GA6205@rot13.obsecurity.org>
In-Reply-To: <20030519110242.A21561@bart.esiee.fr>
References:  <20030519110242.A21561@bart.esiee.fr>

next in thread | previous in thread | raw e-mail | index | archive | help

--5mCyUwZo2JvN/JJP
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, May 19, 2003 at 11:02:42AM +0200, Frank Bonnet wrote:
>=20
> Hi
>=20
> I notice at 5.1-BETA-20030507-JPSNAP=20
> I am able to "su -" anyone ( even root )
> without typing any passwd from a normal
> user account.

I'm not able to quickly reproduce this.

> The machine use nss_ldap if it makes a difference.

It might.  Can you provide all relevant configuration details?

Kris

--5mCyUwZo2JvN/JJP
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (FreeBSD)

iD8DBQE+yMvLWry0BWjoQKURAgHSAKCx4bemSOxIeTBQaCHORvo1Hn/xFQCfUz5Z
vDUUaXULkaVuOu5oTTwOgE8=
=rsKg
-----END PGP SIGNATURE-----

--5mCyUwZo2JvN/JJP--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030519121923.GA6205>