Subject: Re: NetBSD 1.5.2 default configuration
To: None <xs@kittenz.org>
From: Wojciech Bojdol <wojboj@htcon.pl>
List: tech-security
Date: 02/03/2002 17:18:55
On Sun, Feb 03, 2002 at 04:01:54PM +0000, xs@kittenz.org wrote:
> > In my oppinion it's insecure model.
> > Good, tested suid script/program would be better for that.
> 
> Um, isn't that what crontab and suexec are? :)

In your example we need small CGI or PHP script without SUID bit.
THAT program will have to authenticate user and call suexec and crontab.
So there will be x, suexec and crontab.
x and crontab could be more secure.

> > That users need to run pppd as root ?
> 
> yes

for what ?
If they are just dialling in modem is on their stdin/out.
If they're not doing that - for what they use pppd ?

-- 
Wojciech Bojdoł
High-Tech Consulting