[3869] in bugtraq
FALSE ALARM: Re: Another buggy root cron job
daemon@ATHENA.MIT.EDU (Steve Reid)
Wed Dec 25 11:16:54 1996
Date: Wed, 25 Dec 1996 01:34:22 -0800
Reply-To: Steve Reid <steve@edmweb.com>
From: Steve Reid <steve@edmweb.com>
X-To: security@freebsd.org, security-officer@freebsd.org
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In-Reply-To: <Pine.BSF.3.95.961225001440.2706A-100000@bitbucket.edmweb.com>
My face is very red.
From /etc/weekly:
echo /usr/libexec/locate.updatedb | nice -5 su -m nobody 2>&1 |\
fgrep -v 'Permission denied'
It's run as nobody.