[5575] in RedHat Linux List
Re: RedHat4.0 security
daemon@ATHENA.MIT.EDU (Borg)
Fri Nov 22 14:17:12 1996
Date: Fri, 22 Nov 1996 11:13:14 -0800
From: Borg <please_see@my_signature.below>
To: Red Hat Mailing List <redhat-list@redhat.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
Trond Eivind Glomsr=F8d wrote:
> =
> Borg <please_see@my_signature.below> writes:
> =
> > This one should go I think:
> >
> > -rwsr-xr-x 1 root root 138420 Sep 10 08:10 /usr/X11R6/bin/nxt=
erm
> =
> Definitely not. Xterms need to be suid to update wtmp.
But is there any sense in it?? A person who's starting
an xterm has already logged through a tty and had been
registered in wtmp. Please point me to any usefulness
of the fact that I see myself logged 5 times (I normally
run 4 xterms) instead of one? Is making it suid just to
update wtmp and utmp worth the risk of someone exploiting
it?
-- =
#include <disclaimer.h> | *Good pings come in small packets*
Vlad Petersen | Linux: multiuser, multitasking,
Vancouver, B.C | multiplatform, 64-bit and free.
vladimip @ iceonline.com | Ceterum censeo Microsoftam delendam esse
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null