Re: [Security-Discuss] /etc/lilo.conf.old is world readable after new kernel installation

Dick Gevers <dvgevers-qWit8jRvyhVmR6Xm/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Organization If I want to, yes.
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, 12 Oct 2004 12:28:10 +0100, John Tobin wrote about
[Security-Discuss] /etc/lilo.conf.old is world readable after new kernel
installation:

>When you install or remove a kernel /etc/lilo.conf is backed up to
>/etc/lilo.conf.old before modifications are made.  Unfortunately the
>backup is world readable (subject to umask), exposing any passwords
>contained within.  

IMHO one shouldn't put passwords in lilo.conf. If one inserts as
password: "" and then runs lilo, a password will be asked on the
console and a separate file lilo.conf.shs will be created containing the
password in encrypted format.

For clarity's sake, the pwd line should read:

password=""

HTH
Cheers,
=Dick Gevers=

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Encryption is an envelope - the contents are private.

iD8DBQFBbCLrwC/zk+cxEdMRAoLMAJ0cn8N6cUI9D6+XgoUMLfsWKL8kwACg0/1g
+I6cMtQAMiSrH0fJwYtw5kc=
=q3Za
-----END PGP SIGNATURE-----
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.