[5473] in RedHat Linux List
Re: RedHat4.0 security
daemon@ATHENA.MIT.EDU (Tyson D Sawyer)
Thu Nov 21 17:54:58 1996
Date: Thu, 21 Nov 1996 11:59:40 -0500 (EST)
From: Tyson D Sawyer <tyson@rwii.com>
Reply-To: Tyson D Sawyer <tyson@rwii.com>
To: redhat-list@redhat.com
In-Reply-To: <Pine.LNX.3.93.961121105746.30935A-100000@redhat.com>
Resent-From: redhat-list@redhat.com
> -rwsr-xr-x- root root 13708 Oct 28 17:29 /usr/bin/rcp
> -rwsr-xr-x- root root 9572 Oct 28 17:29 /usr/bin/rlogin
> -rwsr-xr-x- root root 6740 Oct 28 17:29 /usr/bin/rsh
>
> Protocol requires client request to come from a privledge port.
... then ...
> -rwsr-sr-x- root tty 51296 Aug 29 16:30 /sbin/dump
> -rwsr-sr-x- root tty 55376 Aug 29 16:30 /sbin/restore
>
> Uses rsh internally for remote dump/restore.
Doesn't the fact that rsh is already suid mean that dump/restore don't
need to be suid to use rsh? There may be other reasons for
dump/restore to be suid but rsh doesn't seem like one of them.
Ty
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null