Subject: re: Fix for PR security/8069: man(1) vulnerability
To: matthew green <mrg@eterna.com.au>
From: Todd Vierling <tv@pobox.com>
List: tech-security
Date: 07/25/1999 20:59:49
On Mon, 26 Jul 1999, matthew green wrote:

:    One drawback (sort of mentioned by Matt Green) is that this makes
:    "nobody" a standard account - it's in our example passwd file, but
:    that doesn't mean that some people don't delete it.
: 
: on second thoughts, using 'nobody' is kinda hoaky, being defined as
: the "unauthorised root" user on NFS, this may actually provide more
: access than you think...

Of course, you've bumped heads with me over this too.

We need an account which means "not supposed to have any privileges", to
which root may drop in some programs.  "noaccess", anyone?

-- 
-- Todd Vierling (tv@pobox.com)