[18213] in Athena Bugs

home help back first fref pref prev next nref lref last post

Re: sgi, sun 8.4.10 /etc/group and xss

daemon@ATHENA.MIT.EDU (Camilla R Fox)
Tue Aug 29 21:34:35 2000

Message-Id: <200008300134.VAA80853@oliver.mit.edu>
To: bugs@MIT.EDU
Date: Tue, 29 Aug 2000 21:34:31 -0400
From: Camilla R Fox <cfox@MIT.EDU>


I further tested the hypothesis that logging in immediately after
someone's logged out of the workstation produces the /etc/group
lossage.  I used a test account a bunch of times on several cluster
machines, counting only those tries which were immediately after a
previous login of mine.

             total tries     errors
sparc5		9		2
ultra5		3		3
sgi indy	1		1

I'm unsure of whether there's a timing thing that makes my hit rate on
ultras so high, or if the numbers are too small to tell.

The error also shows up if I alternate between different test
accounts.

I'm pretty sure that if xss were failing to work almost half the time
for users (and burping an error message to the console), we'd have
heard many more complaints.  This makes me think that the workstation
having chance to do a full reactivate between users cures this.

-Camilla

home help back first fref pref prev next nref lref last post