Full Disclosure mailing list archives

Re: Vulnerability in sourceforge.net


From: steve menard <smenard () nbnet nb ca>
Date: Thu, 22 Jul 2004 21:45:28 -0300

Dang a new Mandrake 10 is currenlty /bin/sh

grep
[@rh8 ]$ grep nobody /etc/passwd
nobody:x:99:99:Nobody:/:/sbin/nologin
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin

[@Mandrake10]$ grep nobody /etc/passwd nobody:x:65534:65534:Nobody:/:/bin/sh
[@Mandrake9.2]$ grep nobody /etc/passwd
nobody:x:65534:65534:Nobody:/:/bin/sh




Anders B Jansson wrote:


nobody:*:32767:32767:Unprivileged user:/nonexistent:/sbin/nologin


Todd Towles wrote:

Does OpenBSD do that?

-----Original Message-----
From: full-disclosure-admin () lists netsys com
[mailto:full-disclosure-admin () lists netsys com] On Behalf Of Gregory A.
Gilliss
Sent: Thursday, July 22, 2004 3:31 PM
To: full-disclosure () lists netsys com
Subject: Re: [Full-disclosure] Vulnerability in sourceforge.net

Really...FreeBSD comes with user nobody set to /sbin/nologin out of the
box. Maybe they should have chosen a better host OS?

G

On or about 2004.07.22 07:49:53 +0000, Todd Towles
(toddtowles () brookshires com) said:


Sounds like they should have configured that page a bit different...made


it

run under a little less access...or said I say..it is a mis-configuration.
=)




_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: