SUMMARY: DEC-Unix V3.2c and C2 Security problem

From: Harald Baumgartner <hmb_at_rosat.mpe-garching.mpg.de>
Date: Wed, 2 Apr 1997 10:39:13 +0200 (MET DST)

Dear Managers,

after reboot in the morning, no one could login to this machine:
Console login: root
Password:xxxxx

        last successfull login...
        last unsuccessfull login...

login:

by telnet the login doesn't appear.

i rebooted in single-user mode:
>>> boot -fl s
# mount -u /
# fsck
# mount -a

with help from DEC-Service (Mrs. Ernst) i found out that the file:
/tcb/files/auth/h/user-file has to much lines, after:
 :u_unsuctty=ttyr0:u_lock_at_:chkent:
                blabla.... appears

i removed the line after chkent: and run /tcb/bin/authck -av

the program tells me, everything is fine, but at the end it produces a core-dump

Now i removed a blank line in the middle from /etc/passwd and rebooted the ma-
chine again.

                        H. Baumgartner
Received on Wed Apr 02 1997 - 11:03:12 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:36 NZDT