From 2b7f64746944a5ca13a3bf623dfffb362681c537 Mon Sep 17 00:00:00 2001 From: thib <> Date: Wed, 20 May 2009 20:37:43 +0000 Subject: [PATCH] Do not fall back to using nobody if _user is missing, but error out. Add a new user _rwalld for rpc.rwalld, and use that instead of nobody, also unconditionally drop to _rwalld not only if rpc.rwalld was started with euid 0 (as root). ok deraadt@ --- src/etc/master.passwd | 1 + 1 file changed, 1 insertion(+) diff --git a/src/etc/master.passwd b/src/etc/master.passwd index 1a7c55f5..72a8d379 100644 --- a/src/etc/master.passwd +++ b/src/etc/master.passwd @@ -42,4 +42,5 @@ _rtadvd:*:92:92::0:0:IPv6 Router Advertisement Daemon:/var/empty:/sbin/nologin _ypldap:*:93:93::0:0:YP to LDAP Daemon:/var/empty:/sbin/nologin _btd:*:94:94::0:0:Bluetooth Daemon:/var/empty:/sbin/nologin _smtpd:*:95:95::0:0:SMTP Daemon:/var/empty:/sbin/nologin +_rwalld:*:96:96::0:0:rpc.rwalld:/var/empty:/sbin/nologin nobody:*:32767:32767::0:0:Unprivileged user for NFS:/nonexistent:/sbin/nologin