Bugtraq mailing list archives

DEC OSF/1 Enhanced Security passwd problem


From: mjf () clark net (Marc J. Fraioli)
Date: Thu, 1 Sep 1994 08:52:17 -0400 (EDT)


I'm having trouble w/ DEC OSF/1 V2.0 Enhanced Security.  Just yesterday, 
the passwd program decided to be very friendly and let anyone (except 
root) change anyone else's password.  I wrote a wrapper for it so that it 
can't do that anymore.

I just checked on my similar system, and it does the same thing.  This
system is pretty isolated (not on the Net), so I don't think it's a
backdoor left behind by a previous intruder.  Could you post or send
your wrapper?  Does anyone know if this occurs in 2.1 or 3.0?  I'll
mention this to our DEC guy...

Marc Fraioli
mjf () clark net



Current thread: