Security

tim at unc.UUCP tim at unc.UUCP
Mon Jul 11 04:21:04 AEST 1983


    It is not true that only login and passwd need to read
/etc/passwd.  The GCOS field is used for maintenance of a user
information database on many systems, requiring that the file be
readable by finger as well.  Of course, finger could be made setuid to
root, or a different file could be used for the database.

______________________________________
The overworked keyboard of Tim Maroney

duke!unc!tim (USENET)
tim.unc at udel-relay (ARPA)
The University of North Carolina at Chapel Hill



More information about the Comp.unix.wizards mailing list