[5580] in RedHat Linux List
Re: RedHat4.0 security
daemon@ATHENA.MIT.EDU (Ben Lindstrom)
Fri Nov 22 14:26:55 1996
Date: Fri, 22 Nov 1996 15:22:14 -0500 (EST)
From: Ben Lindstrom <mouring@sarah.djmix.com>
To: redhat-list@redhat.com
In-Reply-To: <3295FB4A.508C4BDB@my_signature.below>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
On Fri, 22 Nov 1996, Borg wrote:
> Trond Eivind Glomsr=F8d wrote:
> >=20
> > Borg <please_see@my_signature.below> writes:
> >=20
> > > This one should go I think:
> > >
> > > -rwsr-xr-x 1 root root 138420 Sep 10 08:10 /usr/X11R6/bin/nxt=
erm
> >=20
> > Definitely not. Xterms need to be suid to update wtmp.
>=20
> But is there any sense in it?? A person who's starting
> an xterm has already logged through a tty and had been
> registered in wtmp. Please point me to any usefulness
> of the fact that I see myself logged 5 times (I normally
> run 4 xterms) instead of one? Is making it suid just to
> update wtmp and utmp worth the risk of someone exploiting
> it?
I log into your machine via telnet. I set my xhost to let xdisplays from=
=20
you machine to be accepted by mine. Then I type: xterm & and log off..
About 2 seconds later I get an xterm on your machine, and if you do a=20
"who" or "w" I don't show up.
xterm should be in wtmp IMHO. =20
BTW, it seems most of the SUID software requires /dev/ttyXX (for most=20
user apps) or SVGALIB (This one I don't use since I never need it.).
Does anyone know if with some of the new Posix.6 (I believe that's the=20
right specs) that some of this will be done away with and cleaned up? Or=
=20
is it just going to get worse?
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null