[5579] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: RedHat4.0 security

daemon@ATHENA.MIT.EDU (Tyson D Sawyer)
Fri Nov 22 14:26:09 1996

Date: Fri, 22 Nov 1996 14:23:03 -0500 (EST)
From: Tyson D Sawyer <tyson@rwii.com>
Reply-To: Tyson D Sawyer <tyson@rwii.com>
To: redhat-list@redhat.com
In-Reply-To: <3295FB4A.508C4BDB@my_signature.below>
Resent-From: redhat-list@redhat.com

> Trond Eivind Glomsr=F8d wrote:
> >
> > Borg <please_see@my_signature.below> writes:
> >
> > > This one should go I think:
> > >
> > > -rwsr-xr-x   1 root   root     138420 Sep 10 08:10
> > > /usr/X11R6/bin/nxterm=20
> >
> > Definitely not. Xterms need to be suid to update wtmp.
>=20
> But is there any sense in it?? A person who's starting
> an xterm  has already logged through a tty and had been
> registered in wtmp. Please point me to any usefulness
> of the fact that I see myself logged 5 times (I normally
> run 4 xterms) instead of one? Is making it suid just to
> update wtmp and utmp worth the risk of someone exploiting
> it?

I normally login through xdm.  In that case the login may not get
logged.  I'd have to check to be sure.

Ty


--
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
  ________________________________________________________________________
  http://www.redhat.com/RedHat-FAQ   http://www.redhat.com/RedHat-Errata
  http://www.redhat.com/RedHat-Tips  http://www.redhat.com/mailing-lists
  ------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null


home help back first fref pref prev next nref lref last post