Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 10 Jun 1996 11:25:39 +0200 (MET DST)
From:      guido@gvr.win.tue.nl (Guido van Rooij)
To:        taob@io.org (Brian Tao)
Cc:        freebsd-security@freebsd.org, peter@freebsd.org
Subject:   Re: Root rlogins despite /etc/ttys
Message-ID:  <199606100925.LAA10677@gvr.win.tue.nl>
In-Reply-To: <Pine.NEB.3.92.960609232835.23792F-100000@zap.io.org> from Brian Tao at "Jun 9, 96 11:34:35 pm"

next in thread | previous in thread | raw e-mail | index | archive | help
Brian Tao wrote:
>     Could someone confirm this for me?  I noticed that I can rlogin as
> root into a 2.2-960501-SNAP server providing that the .rhosts is setup
> correctly.  The tty assigned to the login session is not marked as
> secure in /etc/ttys.  Previously, the password prompt would appear
> regardless, and root logins denied.

I think this is caused by this commit:
revision 1.6
date: 1995/11/20 23:25:35;  author: peter;  state: Exp;  lines: +2 -3
Stop rlogind from bogusly ignoring an explicit .rhosts file for root.
It still correctly ignores hosts.equiv.  This is now consistant with rshd.


I'll include the author in the Cc: and let him comment about this.
I agree that at least the tty needs to be checked on its secuirty in
the ttys file.

-Guido



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199606100925.LAA10677>