Re: [Security-Discuss] /etc/lilo.conf.old is world readable after new kernel installation
Dick Gevers <dvgevers-qWit8jRvyhVmR6Xm/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Organization | If I want to, yes. |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, 12 Oct 2004 12:28:10 +0100, John Tobin wrote about [Security-Discuss] /etc/lilo.conf.old is world readable after new kernel installation: >When you install or remove a kernel /etc/lilo.conf is backed up to >/etc/lilo.conf.old before modifications are made. Unfortunately the >backup is world readable (subject to umask), exposing any passwords >contained within. IMHO one shouldn't put passwords in lilo.conf. If one inserts as password: "" and then runs lilo, a password will be asked on the console and a separate file lilo.conf.shs will be created containing the password in encrypted format. For clarity's sake, the pwd line should read: password="" HTH Cheers, =Dick Gevers= -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) Comment: Encryption is an envelope - the contents are private. iD8DBQFBbCLrwC/zk+cxEdMRAoLMAJ0cn8N6cUI9D6+XgoUMLfsWKL8kwACg0/1g +I6cMtQAMiSrH0fJwYtw5kc= =q3Za -----END PGP SIGNATURE-----
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________