Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: /bin/login

/bin/login

From: Jon Peatfield <J.S.Peatfield_at_damtp.cam.ac.uk>
Date: Wed, 15 May 1996 21:37:00 BST

Just remove the setuid bit on /bin/login and this "problem" goes away.
(Assuming you have already fixed /etc/utmp,wtmp not to be world writable...)

Not a major security hole, just a bug in applications which trust utmp/wtmp.

 -- Jon
Received on May 15 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos