*BSD News Article 87181


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.carno.net.au!harbinger.cc.monash.edu.au!munnari.OZ.AU!news.ecn.uoknor.edu!news.wildstar.net!news.inetnebr.com!news.enteract.com!insync!feed1.news.erols.com!howland.erols.net!newsxfer3.itd.umich.edu!news.bbnplanet.com!su-news-hub1.bbnplanet.com!news.alt.net!newspost1.alt.net!tiiap.mec.edu!matt
From: matt@tiiap.mec.edu (Matt Bancroft)
Newsgroups: comp.unix.bsd.bsdi.misc
Subject: Re: Security hole
Date: 20 Jan 1997 19:22:30 GMT
Organization: MEC
Lines: 16
Message-ID: <5c0glm$khi@tofu.alt.net>
References: <32DEEC3F.E23@interlog.com> <DERAADT.97Jan18154120@zeus.theos.com> <5bstum$84v@duke.telepac.pt> <5bue0s$psh@tofu.alt.net> <E4AAyu.GD2@news.interactive.net>
X-Newsreader: TIN [version 1.2 PL2]
Xref: euryale.cc.adfa.oz.au comp.unix.bsd.bsdi.misc:5657

: :) : >Numerous ways.  BSDi has many, many easily exploitable security holes.

Ones that give out r00t priveleges to normal users without them even knowing
the root password or being in the group wheel.

: None of these holes are a risk if you have all the latest patches
: installed.

But I suspect many admins havent installed them yet.....

==============================
Matt Bancroft
TIIAP System Administration
matt@mec.edu
bancroft@akamail.com
==============================