[4482] in bugtraq

home help back first fref pref prev next nref lref last post

Netscape Certificate server

daemon@ATHENA.MIT.EDU (Andrew Anderson)
Thu May 15 21:49:24 1997

Date: 	Thu, 15 May 1997 17:30:42 -0400
Reply-To: Andrew Anderson <andrew@STETSON.EDU>
From: Andrew Anderson <andrew@STETSON.EDU>
X-To:         security-notes@netscape.com
To: BUGTRAQ@NETSPACE.ORG

I just saw a nifty little oversight with the Certificate server:

-rwxrwxrwx   1 root     other        333 Apr 28 21:14 S99ifmx

The shell script that starts up the Informix database for
the Certificate server is world writeable in /etc/rc2.d.

Andrew

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Andrew J. Anderson, UNIX System Administrator
Center for Information Technology, Stetson University
Andrew.Anderson@stetson.edu

home help back first fref pref prev next nref lref last post