Re: unsafe file permissions on /usr/bin/login

Manuel Bouyer <[email protected]> Wed, 28 Nov 2018 18:33:59 +0100
Newsgroups gmane.os.netbsd.devel.security
Message-ID <[email protected]>
On Wed, Nov 28, 2018 at 12:27:39PM -0500, JP wrote:
> OK, well I have root with physical access to the box.

Yes, exactly the same way to can log in as root from the login prompt,
as getty calls /usr/bin/login ...

> What is the reason for it being suid? 

So that users can actually use it, I guess ...

-- 
Manuel Bouyer <[email protected]>
     NetBSD: 26 ans d'experience feront toujours la difference
--