Re: unsafe file permissions on /usr/bin/login
JP <[email protected]> Wed, 28 Nov 2018 14:04:28 -0500
| Newsgroups | gmane.os.netbsd.devel.security |
|---|---|
| Message-ID | <CAHN8BqqXBd7rdiozdD-2rhzs6OufDGTeUQuimhKFGCXJxkobZA@mail.gmail.com> |
I've looked at login a little more and see the security measures, but I still don't like it.. At the moment I'm thinking it best (in my very personal opinion) to nologin the root account On Wed, Nov 28, 2018 at 1:20 PM JP <[email protected]> wrote: > well, I can see it... and it's not staying that way on anything I > deploy. > > > On Wed, Nov 28, 2018 at 1:11 PM Manuel Bouyer <[email protected]> > wrote: > >> On Wed, Nov 28, 2018 at 01:09:19PM -0500, JP wrote: >> > I cannot brute force su if I am not in the wheel group. >> >> against root, for other users you can >> >> > >> > I can brute force login regardless of group affiliation. >> >> not against root either. >> >> -- >> Manuel Bouyer <[email protected]> >> NetBSD: 26 ans d'experience feront toujours la difference >> -- >> >