[5580] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: RedHat4.0 security

daemon@ATHENA.MIT.EDU (Ben Lindstrom)
Fri Nov 22 14:26:55 1996

Date: Fri, 22 Nov 1996 15:22:14 -0500 (EST)
From: Ben Lindstrom <mouring@sarah.djmix.com>
To: redhat-list@redhat.com
In-Reply-To: <3295FB4A.508C4BDB@my_signature.below>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com



On Fri, 22 Nov 1996, Borg wrote:

> Trond Eivind Glomsr=F8d wrote:
> >=20
> > Borg <please_see@my_signature.below> writes:
> >=20
> > > This one should go I think:
> > >
> > > -rwsr-xr-x   1 root   root     138420 Sep 10 08:10 /usr/X11R6/bin/nxt=
erm
> >=20
> > Definitely not. Xterms need to be suid to update wtmp.
>=20
> But is there any sense in it?? A person who's starting
> an xterm  has already logged through a tty and had been
> registered in wtmp. Please point me to any usefulness
> of the fact that I see myself logged 5 times (I normally
> run 4 xterms) instead of one? Is making it suid just to
> update wtmp and utmp worth the risk of someone exploiting
> it?

I log into your machine via telnet.  I set my xhost to let xdisplays from=
=20
you machine to be accepted by mine.  Then I type: xterm &  and log off..
About 2 seconds later I get an xterm on your machine, and if you do a=20
"who" or "w" I don't show up.

xterm should be in wtmp IMHO. =20

BTW, it seems most of the SUID software requires /dev/ttyXX (for most=20
user apps)  or SVGALIB (This one I don't use since I never need it.).

Does anyone know if with some of the new Posix.6 (I believe that's the=20
right specs) that some of this will be done away with and cleaned up?  Or=
=20
is it just going to get worse?


--
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
  ________________________________________________________________________
  http://www.redhat.com/RedHat-FAQ   http://www.redhat.com/RedHat-Errata
  http://www.redhat.com/RedHat-Tips  http://www.redhat.com/mailing-lists
  ------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null


home help back first fref pref prev next nref lref last post