Re: unsafe file permissions on /usr/bin/login
JP <[email protected]> Wed, 28 Nov 2018 12:36:38 -0500
| Newsgroups | gmane.os.netbsd.devel.security |
|---|---|
| Message-ID | <CAHN8BqpxY7Urckuhx2LunoHpb80KUGF78=ZyZni6k1zyz2maig@mail.gmail.com> |
and why does a user need to use login from their command line? On Wed, Nov 28, 2018 at 12:34 PM Manuel Bouyer <[email protected]> wrote: > On Wed, Nov 28, 2018 at 12:27:39PM -0500, JP wrote: > > OK, well I have root with physical access to the box. > > Yes, exactly the same way to can log in as root from the login prompt, > as getty calls /usr/bin/login ... > > > What is the reason for it being suid? > > So that users can actually use it, I guess ... > > -- > Manuel Bouyer <[email protected]> > NetBSD: 26 ans d'experience feront toujours la difference > -- >