The debian-private mailing list leak, part 1. Volunteers have complained about Blackmail. Lynchings. Character assassination. Defamation. Cyberbullying. Volunteers who gave many years of their lives are picked out at random for cruel social experiments. The former DPL's girlfriend Molly de Blanc is given volunteers to experiment on for her crazy talks. These volunteers never consented to be used like lab rats. We don't either. debian-private can no longer be a safe space for the cabal. Let these monsters have nowhere to hide. Volunteers are not disposable. We stand with the victims.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: is nobody a security hole?



On Thu, 2 Oct 1997, Christian Hudon wrote:

> On Wed, 1 Oct 1997, Joey Hess wrote:
> > nobody:*:65534:65534:nobody:/tmp:/bin/sh
> Yes, it would indeed be a good ideas to change nobody's home directory...
> I seem to faintly remember a ssh hack that used the fact that nobody's
> home directory was world-writeable. In any case, I think we're better safe
> than sorry. Any major objections out there?

Sorry for my usual "look at other Unices" blurb, but...

That's how they do it in BSDI (4.4BSD-Lite):
chaos:~$ egrep 'nobody|nonroot' /etc/passwd
nobody:*:32767:32766:Unprivileged user:/nonexistent:/sbin/nologin
nonroot:*:65534:32766:Non-root root user for NFS:/nonexistent:/sbin/nologin

[where /sbin/nologin is basically:
echo 'This account is currently not available.'
exit 1
...after a long BSD copyright message;) ]

SunOS (4.2BSD):
pretzel:~> grep nobody /etc/passwd
nobody:*:65534:65534::/:

IRIX (SysV):
cholent:~> egrep 'nobody|noaccess' /etc/passwd
nobody:*:60001:60001:SVR4 nobody uid:/dev/null:/dev/null
noaccess:*:60002:60002:uid no access:/dev/null:/dev/null
nobody:*:-2:-2:original nobody uid:/dev/null:/dev/null

[don't know how they can have two logins with the same name]

Solaris (SysV):
cs2:~> egrep 'nobody|noaccess' /etc/passwd
nobody:x:60001:60001:uid no body:/:
noaccess:x:60002:60002:uid no access:/:

Rasta,
Vadik.

--
Vadim Vygonets * vadik@cs.huji.ac.il * vadik@debian.org * Unix admin
`Mr Beeblebrox, sir,' said the insect in awed wonder, `you're so weird
you should be in movies.' -- `Yeah,' said Zaphod patting the thing on a
glittering pink wing, `and you, baby, should be in real life.' -- HHGttG


--
TO UNSUBSCRIBE FROM THIS MAILING LIST: e-mail the word "unsubscribe" to
debian-private-request@lists.debian.org . 
Trouble?  e-mail to templin@bucknell.edu .