Re: "su" bug

From: Kris Kennaway (kris_at_obsecurity.org)
Date: 05/19/03

  • Next message: Andy Farkas: "Re: man(1) oddity - was: HEADS UP: bzip2(1) compression for manpages..."
    Date: Mon, 19 May 2003 05:19:24 -0700
    To: Frank Bonnet <bonnetf@bart.esiee.fr>
    
    
    

    On Mon, May 19, 2003 at 11:02:42AM +0200, Frank Bonnet wrote:
    >
    > Hi
    >
    > I notice at 5.1-BETA-20030507-JPSNAP
    > I am able to "su -" anyone ( even root )
    > without typing any passwd from a normal
    > user account.

    I'm not able to quickly reproduce this.

    > The machine use nss_ldap if it makes a difference.

    It might. Can you provide all relevant configuration details?

    Kris

    
    



  • Next message: Andy Farkas: "Re: man(1) oddity - was: HEADS UP: bzip2(1) compression for manpages..."

    Relevant Pages

    • SUMMARY: lock on shadow file
      ... prompt for a password if the users account had a *LK* in the shadow file. ... But I seem you should be able to just enter "passwd -d ... The man pages said to unlock a user account you ... admintool, or SMC. ...
      (SunManagers)
    • lock on shadow file
      ... user has *LK* in the shadow file. ... But I seem you should be able to just enter "passwd -d ... The man pages said to unlock a user account you ... admintool, or SMC. ...
      (SunManagers)
    • [HPADM] Re: passwd command
      ... # modprpw -v username ... passwd -u useracct (unlock user account on solaris - hpux does not work) ...
      (HP-UX-Admin)
    • Re: Problem editing footnotes and endnotes
      ... I still can't reproduce either one, and my machine is no longer customized. ... it is probably due to some conflict with the login items/utilities in your user account. ... Re #1--when I double click on a footnote number in Draft view, ... check the Preferences | Edit settings. ...
      (microsoft.public.mac.office.word)
    • Re: Handle leak in Windows 2003 Authorization Manager?
      ... We could not reproduce the token handle leak problem using your modified VB ... sample code ... if a token for that domain user account ...
      (microsoft.public.platformsdk.security)