a thought about UNIX login security

goldfarb at ucf-cs.UUCP goldfarb at ucf-cs.UUCP
Thu Jun 23 14:09:19 AEST 1983


If the unpassworded account that Thompson and Morris found (joe)
had uid=0 and gid=3, just like root, why did they have to go any
further?  They became superuser when they logged in as joe.

--
Ben Goldfarb
uucp:  ...!duke!ucf-cs!goldfarb
ARPA:  goldfarb.ucf-cs at Rand-Relay



More information about the Comp.unix.wizards mailing list