Subject: Re: su and PAM
To: None <current-users@netbsd.org>
From: Christos Zoulas <christos@tac.gw.com>
List: current-users
Date: 03/21/2005 22:10:34
In article <423F8C7F.9040102@rambler.ru>, <sigsegv@rambler.ru> wrote:
>Steven M. Bellovin wrote:
>> In message <423F88D5.9020700@rambler.ru>, sigsegv@rambler.ru writes:
>>
>>>I've just installed base system from netbsd-3 tree and noticed users
>>>belonging to group 'wheel' can gain root access by running 'su', without
>>>password prompt.
>>>Is this intentional?
>>>
>>
>> I can't reproduce that. I just upgraded to 3.99.1 from Saturday,
>> leaving all of the PAM stuff as defaults, and I see a password prompt
>> when I type 'su'.
>>
>>
>> --Prof. Steven M. Bellovin, http://www.cs.columbia.edu/~smb
>>
>>
>>
>
>Dude, I'm running 3.0_BETA, src tree was updated today
>Below is the log attributed to running 'su'
>Any ideas? Something seems broken.
Hey, he was only tryoing to help by giving you another data point.
Are you already root, per chance?
christos