Re: PAM authentication patch - v2

Brian Murphy <[email protected]>
Newsgroups gmane.comp.version-control.cvs.bugs
Message-ID <[email protected]>
Larry Jones wrote:

>Brian Murphy writes:
>  
>
>>If cvs should ever become a daemon and run suid then 
>>this could be a problem.
>>    
>>
>
>Isn't that essentially what happens when you run pserver from inetd as
>root as shown in the manual?
>
>  
>
Yes but you can't make another binary that runs as root
with a different name simply by making a soft link to it.
You would also need to be able to edit inetd.conf
and give the program these permissions when run from
inetd. This requires that you are root or at least that root
has given you the capability to do this. If root has given you
this capability then you can run a root shell and any PAM
configuration won't help.

With cvs, if you are a local user the cvs program can't do
anything the local user can't do anyway.

/Brian
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.