Subject: Re: su and PAM
To: None <current-users@netbsd.org>
From: Christos Zoulas <christos@tac.gw.com>
List: current-users
Date: 03/21/2005 22:10:34
In article <423F8C7F.9040102@rambler.ru>,  <sigsegv@rambler.ru> wrote:
>Steven M. Bellovin wrote:
>> In message <423F88D5.9020700@rambler.ru>, sigsegv@rambler.ru writes:
>> 
>>>I've just installed base system from netbsd-3 tree and noticed users 
>>>belonging to group 'wheel' can gain root access by running 'su', without 
>>>password prompt.
>>>Is this intentional?
>>>
>> 
>> I can't reproduce that.  I just upgraded to 3.99.1 from Saturday, 
>> leaving all of the PAM stuff as defaults, and I see a password prompt 
>> when I type 'su'.
>> 
>> 
>> 		--Prof. Steven M. Bellovin, http://www.cs.columbia.edu/~smb
>> 
>> 
>> 
>
>Dude, I'm running 3.0_BETA, src tree was updated today
>Below is the log attributed to running 'su'
>Any ideas? Something seems broken.

Hey, he was only tryoing to help by giving you another data point.
Are you already root, per chance?

christos