*BSD News Article 26377


Return to BSD News archive

Newsgroups: comp.os.386bsd.bugs
Path: sserve!newshost.anu.edu.au!munnari.oz.au!bunyip.cc.uq.oz.au!harbinger.cc.monash.edu.au!msuinfo!uwm.edu!vixen.cso.uiuc.edu!howland.reston.ans.net!pipex!uknet!cf-cm!paul
From: paul@myrddin.isl.cf.ac.uk (Paul)
Subject: Re: cron..again..fix it already :)
Message-ID: <1994Jan22.105252.23480@cm.cf.ac.uk>
Sender: news@cm.cf.ac.uk (Network News System)
Organization: Intelligent Systems Lab, ELSYM, University of Wales, Cardiff
References: <2hpvvuINNf8u@dds.hacktic.nl>
Date: Sat, 22 Jan 1994 10:52:51 +0000
Lines: 16

In article <2hpvvuINNf8u@dds.hacktic.nl> cor@dds.hacktic.nl (Cor Bosman) writes:
>I was amazed to see that at least one of the _extremely_ trivial
>ways to get root on a *bsd machine still works on FreeBSD.
>A friend of mine just installed the current version, and
>just for the hell of it I tried it..and it still works..
>Maintainers of freebsd..please update the vixiecron that comes
>with it..its a very big security risk. I believe Vixie made a 
>newer, somewhat more secure version.
>Cor...

It's going to be in the next release.

-- 
  Paul Richards, 
  Intelligent Systems Laboratory, ELSYM ,University of Wales, College Cardiff
  Internet: paul@isl.cf.ac.uk,  JANET(UK): RICHARDSDP@UK.AC.CARDIFF