Re: [Security-Discuss] 2006 su problem
"Mario R. Pizzolanti" <[email protected]> Tue, 18 Oct 2005 13:14:23 +0300
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Organization | Zavood OÜ |
| Message-ID | <[email protected]> |
Anne Wilson wrote: >On Tuesday 18 Oct 2005 04:05, AAW wrote: > > >>msec will probably overwrite your changes, Anne. You can either up >>your security level to 3 (Higher) or customize msec (see man msec, >>man mseclib for info, also /usr/share/doc/msec-<version>/*). I didn't >>see that option listed in draksec, so you'd need to add the following >>to /etc/security/msec/level.local (create if needed): >> enable_pam_root_from_wheel(no) >> >> >> >I'm very concerned about this, Arn. Erwann says that the line now is >"auth sufficient pam_succeed_if.so use_uid user ingroup wheel" >so anyone who gains my relatively insecure personal password has full >access to the system? That's not good enough. I trust me, alright, >but this is too big a hole to swallow. I wonder why the change was >made? I'll try your method to block it. > >Anne > > What security level are you using?
message.footer
(text/plain, 232 B)
____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________