Re: [Security-Discuss] 2006 su problem
Anne Wilson <[email protected]> Tue, 18 Oct 2005 10:33:54 +0100
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On Tuesday 18 Oct 2005 04:05, AAW wrote: > > msec will probably overwrite your changes, Anne. You can either up > your security level to 3 (Higher) or customize msec (see man msec, > man mseclib for info, also /usr/share/doc/msec-<version>/*). I didn't > see that option listed in draksec, so you'd need to add the following > to /etc/security/msec/level.local (create if needed): > enable_pam_root_from_wheel(no) > I'm very concerned about this, Arn. Erwann says that the line now is "auth sufficient pam_succeed_if.so use_uid user ingroup wheel" so anyone who gains my relatively insecure personal password has full access to the system? That's not good enough. I trust me, alright, but this is too big a hole to swallow. I wonder why the change was made? I'll try your method to block it. Anne -- Registered Linux User No.293302 (http://counter.li.org/) Mandriva hints & tips: http://twiki.mdklinuxfaq.org
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (GNU/Linux) iD8DBQBDVMGIkFAvMr/nNX8RAv2NAJ92KaD5XyDL3M9FO9cMmKVAswZyrACeJ+fn FHAYHW9Wz8ghHXIbaxOj8zg= =9sYO -----END PGP SIGNATURE-----