At 14:27 -0700 10/18/2001, Wilfredo S�nchez wrote:
>By default you set up an account which is in the admin group.  The
>root directory of the filesystem is writeable by group admin, as are
>/Applications and /Library and other things.

About which sendmail complained the first time it tried to mail the output
of the daily cron job.  So I fixed it, without visible ill effect so far
(since March 25).  I do have to remember to fix it again every time I run
one of Apple's installers, which carefully make / group writeable again.

So far, I haven't found a need to "enable" root (I root about as a basic
part of my job, on other machines).  So the only way for me to "be"
root--as opposed to getting the power via sudo--is to exploit this really
annoying hole.

  --John
--
John Baxter   [EMAIL PROTECTED]      Port Ludlow, WA, USA

Reply via email to