Subject: re: Fix for PR security/8069: man(1) vulnerability
To: Simon Burge <simonb@netbsd.org>
From: matthew green <mrg@eterna.com.au>
List: tech-security
Date: 07/26/1999 10:00:20
   
   One drawback (sort of mentioned by Matt Green) is that this makes
   "nobody" a standard account - it's in our example passwd file, but
   that doesn't mean that some people don't delete it.


on second thoughts, using 'nobody' is kinda hoaky, being defined as
the "unauthorised root" user on NFS, this may actually provide more
access than you think...


unfortunately, i believe 'nobody' is used in quite a lot of places..