[4482] in bugtraq
Netscape Certificate server
daemon@ATHENA.MIT.EDU (Andrew Anderson)
Thu May 15 21:49:24 1997
Date: Thu, 15 May 1997 17:30:42 -0400
Reply-To: Andrew Anderson <andrew@STETSON.EDU>
From: Andrew Anderson <andrew@STETSON.EDU>
X-To: security-notes@netscape.com
To: BUGTRAQ@NETSPACE.ORG
I just saw a nifty little oversight with the Certificate server:
-rwxrwxrwx 1 root other 333 Apr 28 21:14 S99ifmx
The shell script that starts up the Informix database for
the Certificate server is world writeable in /etc/rc2.d.
Andrew
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Andrew J. Anderson, UNIX System Administrator
Center for Information Technology, Stetson University
Andrew.Anderson@stetson.edu