They'd have to have root permissions to write to the /etc/passwd file which
they only have read and the shadow file is strictly root only.
They woul dhave to find an exploit to which they have root priviledges and
THEN can do damage
thanks,
George Vieira
Network Administrator
Citadel Computer Systems P/L
http://www.citadelcomputer.com.au
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Monday, 22 May 2000 1:31 PM
To: [EMAIL PROTECTED]
Subject: [SLUG] Mysterious Userids Injected in /etc/passwd
I realise there are security issues with Redhat 6.0 and will be installing
6.2
soon. In the meantime, what is the most likely method someone could use to
inject new userids in the /etc/passwd and /etc/shadow files? There is no
record
of access by telnet, ftp nor anything else.
Thanks
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text