Re: [Security-Discuss] 2006 su problem

"Mario R. Pizzolanti" <[email protected]> Tue, 18 Oct 2005 13:14:23 +0300
Newsgroups gmane.linux.mandrake.security.general
Organization Zavood OÜ
Message-ID <[email protected]>
Anne Wilson wrote:

>On Tuesday 18 Oct 2005 04:05, AAW wrote:
>  
>
>>msec will probably overwrite your changes, Anne. You can either up
>>your security level to 3 (Higher) or customize msec (see man msec,
>>man mseclib for info, also /usr/share/doc/msec-<version>/*). I didn't
>>see that option listed in draksec, so you'd need to add the following
>>to /etc/security/msec/level.local (create if needed):
>>	enable_pam_root_from_wheel(no)
>>
>>    
>>
>I'm very concerned about this, Arn.  Erwann says that the line now is
>"auth       sufficient   pam_succeed_if.so use_uid user ingroup wheel"
>so anyone who gains my relatively insecure personal password has full 
>access to the system?  That's not good enough.  I trust me, alright, 
>but this is too big a hole to swallow.  I wonder why the change was 
>made?    I'll try your method to block it.
>
>Anne
>  
>
What security level are you using?
message.footer (text/plain, 232 B)
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________