DragonFly users List (threaded) for 2007-03
DragonFly BSD
DragonFly users List (threaded) for 2007-03
[Date Prev][Date Next]  [Thread Prev][Thread Next]  [Date Index][Thread Index]

Re: To be a new DFly commiter


From: Joerg Sonnenberger <joerg@xxxxxxxxxxxxxxxxx>
Date: Fri, 16 Mar 2007 20:58:37 +0100
Mail-followup-to: users@crater.dragonflybsd.org

On Fri, Mar 16, 2007 at 06:07:07PM +0100, Grzegorz B?ach wrote:
> When you do buffer-overflow in passwd you can exec any code with root priviledges,
> but with tcb you must change root password to run code with root priviledges,
> and administrator will see this faster.

Who said that I want to change the root password? I can easily just
create a new user with uid 0, login remotely as that and change the
entry back. Very little log pollution and that can be easily taken care
of.

Joerg



[Date Prev][Date Next]  [Thread Prev][Thread Next]  [Date Index][Thread Index]