Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: PAM applications running as root (Was Re: WebTrends Enterprise
From: alan () LXORGUK UKUU ORG UK (Alan Cox)
Date: Fri, 15 Oct 1999 17:51:15 +0100


It is NOT a requirement of the PAM framework that application be running as
root.  There are two cases though that make login type applications need to
run as root.

      1) The password is stored in /etc/shadow which only root can read
         If the password was in NIS/NIS+/LDAP then the authentication
         could succeed are an ordinary user.

This is not correct either. A good PAM implementation supports shadow
authentication (although not update) via setuid helpers

Alan


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]