OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 2nd quarter (Apr-Jun) 1994: Re: "passwd -F" vulnerability?

Re: "passwd -F" vulnerability?

Steve Simmons (scslokkur.dexter.mi.us)
Wed, 11 May 1994 07:29:05 -0400 (EDT)

Pat Myrto wrote:

>   So what?  One can copy /etc/passwd and edit it with an EDITOR.  So?
>   Login reads /etc/passwd, not whatever file the user chooses. . . .
>   Its not a problem.

Do

	passwd -F /etc/shadow

Now the shadow password file is visible in /var/adm/messages.