Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 28 Jul 1997 23:02:15 -0700 (PDT)
From:      Vincent Poy <vince@mail.MCESTATE.COM>
To:        "Jordan K. Hubbard" <jkh@time.cdrom.com>
Cc:        "Jonathan A. Zdziarski" <jonz@netrail.net>, "[Mario1-]" <Mario1@primenet.com>, JbHunt <johnnyu@accessus.net>, Robert Watson <robert+freebsd@cyrus.watson.org>, Tomasz Dudziak <loco@onyks.wszib.poznan.pl>, security@FreeBSD.ORG
Subject:   Re: security hole in FreeBSD 
Message-ID:  <Pine.BSF.3.95.970728230037.3844E-100000@mail.MCESTATE.COM>
In-Reply-To: <6894.870155971@time.cdrom.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, 28 Jul 1997, Jordan K. Hubbard wrote:

=)> 	Just a update on how the break-in was done after the hacker was
=)> confronted on irc.  
=)> 
=)> 	Apparently FreeBSD ships with .rhosts in the root account.  Using
=)
=)No, FreeBSD does not ship with .rhosts in the root account.  This must
=)have been a local change.  If you do not believe this then simply do a
=)fresh installation of FreeBSD and see for yourself - sorry, you shot
=)your own feet off here. :-)

	I just verified it and you're right.  It doesn't but what about
the adduser program?  I have a tarball of my home directory and there is
no .rhosts there either.  I wonder how the .rhosts got there in the first
place.  


Cheers,
Vince - vince@MCESTATE.COM - vince@GAIANET.NET           ________   __ ____ 
Unix Networking Operations - FreeBSD-Real Unix for Free / / / / |  / |[__  ]
GaiaNet Corporation - M & C Estate                     / / / /  | /  | __] ]  
Beverly Hills, California USA 90210                   / / / / / |/ / | __] ]
HongKong Stars/Gravis UltraSound Mailing Lists Admin /_/_/_/_/|___/|_|[____]





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.95.970728230037.3844E-100000>