Re: securityhole /proc/sys/kernel/domainname

Andreas Kostyrka (andreas@medman.ag.or.at)
Tue, 20 Feb 1996 23:01:00 +0100 (MET)


On Tue, 20 Feb 1996, Christoph Lameter wrote:

> How about requiring root priviledges for getpwent()?
>
> But then passwd needs to run with root priviledges.
It does already. But that doesn't work either, because getpwent() is
defined to be available to user programs, that watn to scan the password
file.
(Consider a ``optimized'' ls, that reads the whole passwd before doing
a listing, instead of using the access methods per uid?)
getpwent() doesn't have to return the encrypted password, but the other
fields may be needed for all kind of stuff. (How do you implement a
search by Full Name without it? You know, that none of your users needs
to do this? Really SURE? And are you sure, that no users working on NIS
systems need this? (You are proposing changes to the kernel/libc!) Still
SURE?)

Andreas

--
Andreas Kostyrka
Email: andreas@medman.ag.or.at
Fax: +43/1/7070750 Tel: +43/1/7077571, +43/664/3020166 (cellular)
Copyright 1996 Andreas Kostyrka.  Microsoft Network is prohibited from
redistributing this work in any form, in whole or in part.