Re: [Security-Discuss] /etc/lilo.conf.old is world readable after new kernel installation

FACORAT Fabrice <[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Le mardi 12 Octobre 2004 20:31, Dick Gevers a écrit :
> On Tue, 12 Oct 2004 12:28:10 +0100, John Tobin wrote about
> [Security-Discuss] /etc/lilo.conf.old is world readable after new kernel
>
> installation:
> >When you install or remove a kernel /etc/lilo.conf is backed up to
> >/etc/lilo.conf.old before modifications are made.  Unfortunately the
> >backup is world readable (subject to umask), exposing any passwords
> >contained within.
>
> IMHO one shouldn't put passwords in lilo.conf. If one inserts as
> password: "" and then runs lilo, a password will be asked on the
> console and a separate file lilo.conf.shs will be created containing the
> password in encrypted format.
>
> For clarity's sake, the pwd line should read:
>
> password=""

thanks for the tips, didn't knew that and don't remeùber having read that in 
manpage ...

-- 
La chance n'existe pas. Ce que vous appelez chance, c'est essentiellement
l'attention que certains accordent aux détails les plus infimes.
Winston Churchill
message.footer (text/plain, 239 B)
____________________________________________________
Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com
Join the Club : http://www.mandrakeclub.com
____________________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.