Re: unsafe file permissions on /usr/bin/login

JP <[email protected]> Wed, 28 Nov 2018 12:36:38 -0500
Newsgroups gmane.os.netbsd.devel.security
Message-ID <CAHN8BqpxY7Urckuhx2LunoHpb80KUGF78=ZyZni6k1zyz2maig@mail.gmail.com>
and why does a user need to use login from their command line?

On Wed, Nov 28, 2018 at 12:34 PM Manuel Bouyer <[email protected]>
wrote:

> On Wed, Nov 28, 2018 at 12:27:39PM -0500, JP wrote:
> > OK, well I have root with physical access to the box.
>
> Yes, exactly the same way to can log in as root from the login prompt,
> as getty calls /usr/bin/login ...
>
> > What is the reason for it being suid?
>
> So that users can actually use it, I guess ...
>
> --
> Manuel Bouyer <[email protected]>
>      NetBSD: 26 ans d'experience feront toujours la difference
> --
>