Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 22 Sep 2001 15:00:05 -0700
From:      Cy Schubert - ITSD Open Systems Group <Cy.Schubert@uumail.gov.bc.ca>
To:        Joseph Mallett <jmallett@NewGold.NET>
Cc:        "Andrey A. Chernov" <ache@nagual.pp.ru>, security@FreeBSD.ORG, rwatson@FreeBSD.ORG, current@FreeBSD.ORG, developers@FreeBSD.ORG
Subject:   Re: ~/.login_conf disabling exact reasons wanted 
Message-ID:  <200109222200.f8MM0GB29509@cwsys.cwsent.com>
In-Reply-To: Your message of "Sat, 22 Sep 2001 21:21:32 -0000." <20010922212132.A10857@NewGold.NET> 

next in thread | previous in thread | raw e-mail | index | archive | help
In message <20010922212132.A10857@NewGold.NET>, Joseph Mallett writes:
> On Sat, Sep 22, 2001 at 03:17:52PM +0400, Andrey A. Chernov wrote:
> > Only "me" class can be defined in ~/.login_conf, anything else ignored 
> > there. And "me" class picked up only when permissions are set to user 
> > mode, at the end of setusercontext(). And "copyright" and "welcome" are 
> > not overwriteable from "me" class in any case.
> 
> I was able to overwrite the settings for the `default' class, which 
> happens to be my login class, and was able to get master.passwd to 
> print... This was 4.x though, not CURRENT, so maybe this is something that 
> wasn't affected in CURRENT, and that's what you're referring to, or 
> something.

I am able to exploit the bug in 4.4-RC.  I am not able to exploit 
4.4-RELEASE.


Regards,                         Phone:  (250)387-8437
Cy Schubert                        Fax:  (250)387-5766
Team Leader, Sun/Alpha Team   Internet:  Cy.Schubert@osg.gov.bc.ca
Open Systems Group, ITSD
Ministry of Management Services
Province of BC




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-current" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200109222200.f8MM0GB29509>