[SLE] setting multiple user id to 0 (zero) is bad ! Why?

From: Chadley Wilson (chadley_at_pinteq.co.za)
Date: 06/30/05

  • Next message: Peter Nikolic: "Re: [SLE] Is sound management ready for the 'Linux Desktop'?"
    To: suse-linux-e@suse.com
    Date: Thu, 30 Jun 2005 09:53:30 +0200
    
    

    Greetings,

    Friends, I am in a situation with my one clients who use - (Yes that one
    again!!), uucp.

    Now their previous techies set all the user id's for the system to 0 (zero)
    Oh! and all the GID's as well.
    Now I have come in and had to fix this, but I get resistance.

    I have only one good reason why not to right now,

    with uucp on one site all the files are transfered but not removed from the
    queue, only when I set the user id to 14 (IIRC) and the GID to 512, and of
    course changed all the on the relevant configs and files, would it clean the
    remote queue.
    This reason however has been flawed as we have other sites that work properly
    with all the UID's and GID's set to 0 (zero).

    I need more reasons, explaining how this affects the system integrity, and
    functionality, the trick here is they don't give two hoots about the security
    aspect. So to win my case professionally and cleverly, I ask for real
    opinions and reasons.

    Could you please assist.

    -- 
    --
    Chadley Wilson
    Production Line Superintendant
    Pinnacle Micro
    Manufacturers of Proline Computers
    ====================================
    Exercise freedom, Use LINUX
    =====================================
    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Peter Nikolic: "Re: [SLE] Is sound management ready for the 'Linux Desktop'?"

    Relevant Pages

    • Re: [SLE] setting multiple user id to 0 (zero) is bad ! Why?
      ... On 6/30/05, Chadley Wilson wrote: ... > again!!), uucp. ... > This reason however has been flawed as we have other sites that work properly ... that it was due to sloppy and lazy security practices. ...
      (SuSE)
    • Re: killing UUCP
      ... > Aside from the SUID/SGID stuff that pops up via my finds, ... > simply see no reason to have any UUCP stuff on these boxes. ... create a local DoS of sorts... ...
      (FreeBSD-Security)