*BSD News Article 25056


Return to BSD News archive

Path: sserve!newshost.anu.edu.au!munnari.oz.au!news.Hawaii.Edu!ames!agate!howland.reston.ans.net!torn!nott!cunews!revcan!micor!latour!zone4!zone4!not-for-mail
From: roo@zone4.ocunix.on.ca (Andrew Low)
Newsgroups: comp.os.386bsd.bugs
Subject: Re: 386bsd login security bug
Date: 15 Dec 1993 23:47:39 -0500
Organization: Zone4
Lines: 13
Message-ID: <2eop9b$sg7@zone4.ocunix.on.ca>
References: <chrisjCHypxr.94s@netcom.com> <2ejpdk$jhs@zone4.ocunix.on.ca>
NNTP-Posting-Host: zone4.ocunix.on.ca

In article <2ejpdk$jhs@zone4.ocunix.on.ca> 
roo@zone4.ocunix.on.ca (Andrew Low) writes:
>
>I just discovered this myself and was very suprised.  I was trying
>to allow 'root' to have no password, but only allow root logins from
>the console (secure) or let people in the group wheel 'su' to root.
>

I was informed that in NetBSD current this has been fixed

-- 
---->InSaNiTyNoW!<---- ! (H)acker ! There is a ! (Cr)acker
roo@zone4.ocunix.on.ca ! (H)onest ! difference ! (Cr)iminal