[17800] in Athena Bugs
security hole?
daemon@ATHENA.MIT.EDU (Ron Hoffmann)
Thu Apr 20 14:45:57 2000
Date: Thu, 20 Apr 2000 14:41:00 -0400 (EDT)
Message-Id: <200004201841.OAA22217@Paddington.MIT.EDU>
From: Ron Hoffmann <hoffmann@MIT.EDU>
To: bugs@mit.edu
Cc: hoffmann@mit.edu
Try this and see if you can duplicate it.
Take an ultra* with the current field release,
detach it's packs and attach decstation packs.
Now log off.
Before it reactivates and gets useful packs,
try and log in as root. You will find that
after providing the username and <cr> you'll
get a bunch of errors, and then a shell prompt.
This without ever having provided a password.
-Ron