[12209] in bugtraq
Re: SCO OpenServer 5.0.5 overwrite /etc/shadow
daemon@ATHENA.MIT.EDU (Bela Lubkin)
Tue Oct 12 02:32:00 1999
Message-Id: <199910111437.aa00410@rubidium.pdev.sco.com>
Date: Mon, 11 Oct 1999 14:37:33 -0700
Reply-To: Bela Lubkin <belal@SCO.COM>
From: Bela Lubkin <belal@SCO.COM>
X-To: Brock Tellier <btellier@webley.com>
To: BUGTRAQ@SECURITYFOCUS.COM
Brock Tellier wrote:
> Any user may overwrite any file with group auth (i.e. /etc/shadow,
[sad tale which does not require repeating]
Brock, I would like to publically thank you for the auditing you are
doing. And, I suppose, hang my head in shame at the problems you're
finding in the process.
You are being heard. Various people and groups at SCO are scrambling to
fix what's been mentioned. Your discoveries are also prompting various
proactive security audit efforts. I'm not in a position to make any
promises about results. I do know that we have good intentions and will
try to deliver on them as well as we can...
Not an official SCO representative --
>Bela<