Re: strange result when typing wrong password
On 05 Jun 2002 22:18:12 +0200
nisse@lysator.liu.se (Niels Möller) wrote:
> Niklas Söderlund <niklas.soderlund@chello.se> writes:
>
> > Use `login USER' to login, or `help' for more information.
> > login> grep root /etc/passwd
> > root:<encrypted password>:0:0:root:/root:/bin/bash
> >
> > Anyone know why it is like this? Is it possible to use shadow-file?
>
> Even if not using shadow passwords, it would make sense to make
> /etc/password not readable by the not-logged-in user. You still need
> to be able to query the passwd server though, otherwise login wouldn't
> work.
>
> /Niels
Yup, but since /bin/login is suid:ed as root, it should be harmless
to do chmod 640 /etc/passwd?
--
To UNSUBSCRIBE, email to debian-hurd-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Reply to: