Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 10 Aug 2016 22:16:46 -0700
From:      Ngie Cooper <yaneurabeya@gmail.com>
To:        "O. Hartmann" <ohartman@zedat.fu-berlin.de>
Cc:        freebsd-current <freebsd-current@freebsd.org>, freebsd-ports <freebsd-ports@freebsd.org>
Subject:   Re: Passwordless accounts vi ports!
Message-ID:  <B77B39ED-9A75-4C36-A1F5-4F76CA19E42D@gmail.com>
In-Reply-To: <20160811070505.2c1a1466@freyja.zeit4.iv.bundesimmobilien.de>
References:  <20160811070505.2c1a1466@freyja.zeit4.iv.bundesimmobilien.de>

next in thread | previous in thread | raw e-mail | index | archive | help

> On Aug 10, 2016, at 22:05, O. Hartmann <ohartman@zedat.fu-berlin.de> wrote=
:
>=20
> I just checked the security scanning outputs of FreeBSD and found this
> surprising result:
>=20
> [...]
> Checking for passwordless accounts:
> polkitd::565:565::0:0:Polkit Daemon User:/var/empty:/usr/sbin/nologin
> pulse::563:563::0:0:PulseAudio System User:/nonexistent:/usr/sbin/nologin
> saned::194:194::0:0:SANE Scanner Daemon:/nonexistent:/bin/sh
> clamav::106:106::0:0:Clamav Antivirus:/nonexistent:/usr/sbin/nologin
> bacula::910:910::0:0:Bacula Daemon:/var/db/bacula:/usr/sbin/nologin
> [...]
>=20
> Obviously, some ports install accounts but do not secure them as there is a=
n
> empty password.
>=20
> I consider this not a feature, but a bug.

saned is the only one that might concern me because the login shell isn't no=
login(1).

Cheers,
-Ngie=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?B77B39ED-9A75-4C36-A1F5-4F76CA19E42D>