Re: security hole in FreeBSD

[ Available lists | Index of freebsd-security | Month of Jul 1997 | Week of 28 Jul 1997 | Raw email | View thread | Wrap long lines | Reply | Tag ]
From
Vincent Poy <vince@mail.MCESTATE.COM>
Date
28 Jul 1997 23:02:55
Subject
Re: security hole in FreeBSD
Message-ID
Pine.BSF.3.95.970728230037.3844E-100000@mail.MCESTATE.COM

In reply to

[ Hide this part ]
On Mon, 28 Jul 1997, Jordan K. Hubbard wrote:

=)> Just a update on how the break-in was done after the hacker was
=)> confronted on irc.
=)>
=)> Apparently FreeBSD ships with .rhosts in the root account. Using
=)
=)No, FreeBSD does not ship with .rhosts in the root account. This must
=)have been a local change. If you do not believe this then simply do a
=)fresh installation of FreeBSD and see for yourself - sorry, you shot
=)your own feet off here. :-)

I just verified it and you're right. It doesn't but what about
the adduser program? I have a tarball of my home directory and there is
no .rhosts there either. I wonder how the .rhosts got there in the first
place.


Cheers,
Vince - vince@MCESTATE.COM - vince@GAIANET.NET ________ __ ____
Unix Networking Operations - FreeBSD-Real Unix for Free / / / / | / |[__ ]
GaiaNet Corporation - M & C Estate / / / / | / | __] ]
Beverly Hills, California USA 90210 / / / / / |/ / | __] ]
HongKong Stars/Gravis UltraSound Mailing Lists Admin /_/_/_/_/|___/|_|[____]




Elapsed time: 0.114 seconds