On Mon, 10 Jun 2002, Binand Raj S. wrote: > Authentication is done against /etc/shadow, which is usually > readable only by root. Hence su should be setuid root.
I would think all authentication would be done by consolehelper (through pam), which is setuid root anyway. But then RH 6 a long time ago (will check at home), and consolehelper did have a local root exploit back then (allowed .. in the path to a conf file, which in turn could refer to any library which would run as root). -- "Don't think; let the machine do it for you!" -- E. C. Berkeley _______________________________________________________________ Don't miss the 2002 Sprint PCS Application Developer's Conference August 25-28 in Las Vegas - http://devcon.sprintpcs.com/adp/index.cfm?source=osdntextlink _______________________________________________ linux-india-help mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/linux-india-help
