Re: unsafe file permissions on /usr/bin/login

JP <[email protected]> Wed, 28 Nov 2018 14:04:28 -0500
Newsgroups gmane.os.netbsd.devel.security
Message-ID <CAHN8BqqXBd7rdiozdD-2rhzs6OufDGTeUQuimhKFGCXJxkobZA@mail.gmail.com>
I've looked at login a little more and see the security measures, but I
still don't like it..

At the moment I'm thinking it best (in my very personal opinion) to nologin
the root account

On Wed, Nov 28, 2018 at 1:20 PM JP <[email protected]> wrote:

> well, I can see it...     and it's not staying that way on anything I
> deploy.
>
>
> On Wed, Nov 28, 2018 at 1:11 PM Manuel Bouyer <[email protected]>
> wrote:
>
>> On Wed, Nov 28, 2018 at 01:09:19PM -0500, JP wrote:
>> > I cannot brute force su if I am not in the wheel group.
>>
>> against root, for other users you can
>>
>> >
>> > I can brute force login regardless of group affiliation.
>>
>> not against root either.
>>
>> --
>> Manuel Bouyer <[email protected]>
>>      NetBSD: 26 ans d'experience feront toujours la difference
>> --
>>
>