Bugtraq mailing list archives

Re: bin ownership problem


From: perry () imsi com (Perry E. Metzger)
Date: Thu, 19 May 1994 14:02:52 -0400


Brad Powell - Sun CIS says:
we had to change the setuid to bin when we changed the ownership of /etc
to bin. Otherwise you couldn't use chesstool to break root :-) :-)

(that was a joke for the smiley impaired btw)

Seriously though this was done so that it could write a high score file.

I've always gone through /usr/games on every SunOS version I get and
changed everything to be suid "games" and created a games ID. Makes
life much safer. Then people can only use the security holes in games
to cheat at the other games. I've always wondered why sun doesn't do
that on their own.

Perry



Current thread: