Bug#4465: security hole in netdiag package

1996-09-12 Thread Michael Meskes
Peter Tobias writes: > > Package: netdiag > Version: 0.2-3 > > The postinst script copies the tcpdump binary from the tcpdump > package and the traceroute binary from the netstd package to /usr/bin > and makes them setuid root.adm. This allows all users in the existing > adm group to use tcpdump

Bug#4465: security hole in netdiag package

1996-09-10 Thread Dirk . Eddelbuettel
Christoph> tcpdump and traceroute are essential network diagnostic Christoph> tools. But only for root. Christoph> Somehow they need to fit into the scheme. Before the netdiag Christoph> package I manually changed permissions on all machine I Christoph> installed because our administr

Re: Bug#4465: security hole in netdiag package

1996-09-10 Thread Christoph Lameter
Alright I tried all the ideas I had. What shall I do to get consistency with network diagnostic tools that should be be in the hads of troublemakers? I know the adm group is not the right one. Shall I try to set up a new group of users being able to use network diagnostics? tcpdump and traceroute

Bug#4465: security hole in netdiag package

1996-09-10 Thread Peter Tobias
Package: netdiag Version: 0.2-3 The postinst script copies the tcpdump binary from the tcpdump package and the traceroute binary from the netstd package to /usr/bin and makes them setuid root.adm. This allows all users in the existing adm group to use tcpdump to get the unencrypted passwords that