Re: unsafe file permissions on /usr/bin/login

JP <[email protected]> Wed, 28 Nov 2018 13:20:42 -0500
Newsgroups gmane.os.netbsd.devel.security
Message-ID <CAHN8BqqOfet50y-tOfmzwEeWS2tzY7SUNC9e44bRD=+1vjWPwQ@mail.gmail.com>
well, I can see it...     and it's not staying that way on anything I
deploy.


On Wed, Nov 28, 2018 at 1:11 PM Manuel Bouyer <[email protected]>
wrote:

> On Wed, Nov 28, 2018 at 01:09:19PM -0500, JP wrote:
> > I cannot brute force su if I am not in the wheel group.
>
> against root, for other users you can
>
> >
> > I can brute force login regardless of group affiliation.
>
> not against root either.
>
> --
> Manuel Bouyer <[email protected]>
>      NetBSD: 26 ans d'experience feront toujours la difference
> --
>