develooper Front page | perl.perl5.porters | Postings from November 1999

Re: getspnam-support

Thread Previous | Thread Next
From:
Matthias Urlichs
Date:
November 29, 1999 05:19
Subject:
Re: getspnam-support
Message ID:
19991129141947.B5713@noris.de
Hi,

Dan Sugalski:
> >Returning the shadow data just because you're running as root is a possible
> >security hole.
> 
> If you're running as root there are no security holes since there is no
> security. You can already do anything you want, so why quibble over this?

Consider a setuid-root program which doesn't need the actual password,
but which calls getpw*() for other reasons.

Conceivably, that program could be induced to leak the password.

-- 
Matthias Urlichs  |  noris network GmbH   |   smurf@noris.de  |  ICQ: 20193661
The quote was selected randomly. Really.    |      http://www.noris.de/~smurf/
-- 
Password:

Thread Previous | Thread Next


nntp.perl.org: Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at ask@perl.org | Group listing | About