[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

/etc/shadow world-readable



hi,

i just realized that /etc/shadow are mode 644 (owned by root:root) on
two of my systems. (Another two machines are not affected, however)

i'm sure this change was not made manually, but have no clue what
could have caused it.
a grep in /var/lib/dpkg/info didn't show anything.

anyone got this, too?


machines are:

1. old potato machine
(routing+filtering, proxy, afbackup)			[not affected]

2. newer, but not up-to-date potato machine 
(apache, qmail, with shellaccouts for users)		[AFFECTED]

3. up-to-date potato machine
(routing, samba+proftp fileserver)			[not affected]

4. up-to-date woody machine
(personal workstation, X, gnome, devel)			[AFFECTED]


the only thing i realise these machines have in common:
machines 1+3 are mainly accessed with ssh-rsa keys and are using
pam_unix for other authenication,
2+4 use pam_pwdb and are frequently accessed without rsa-keys

but i could not reproduce the problem so far


any ideas?

-- 
CU,		  / Friedrich-Alexander University Erlangen, Germany
Martin Waitz	//  [Tali on IRCnet]  [tali.home.pages.de] _________
______________/// - - - - - - - - - - - - - - - - - - - - ///
dies ist eine manuell generierte mail, sie beinhaltet    //
tippfehler und ist auch ohne grossbuchstaben gueltig.   /

Attachment: pgpYwQ70mRMy1.pgp
Description: PGP signature


Reply to: