68 Commits (f6665ab14171195aaaea5af9b84e609b23876d8c)

Author SHA1 Message Date
  millert be9f1ce9eb Use $file shorthand instead of specifying /var/backups/disklabel.$d. 20 years ago
  millert a117f51a18 store a copy of the disklabel for mounted filesystems and report changes 20 years ago
  otto 8610a95b88 Update based on PR 2208: 21 years ago
  sturm 6a07898f48 fix regexp for group names 21 years ago
  millert 647d0cdbb1 when testing passwd(5) expire field, force its value to an int before 21 years ago
  millert c3a8fa3c18 Fix setting of umaskset. Also, there is no need to use TMP3 for 21 years ago
  millert ba8f3ee996 We need the "/ 10" in the group writability check after all; marc@ 21 years ago
  millert c877ad0d6f Make the test for unsafe umask more bullet-proof. With help from marc@ 21 years ago
  avsm ef01e76670 some more extra mktemp randomness; millert@ ok 21 years ago
  grange bccca5e422 The hyphen in regexp should really be escaped 21 years ago
  millert 2e71a0e51b Add dot ('.') in usernames too for consistency with adduser/useradd. 21 years ago
  millert cf8c1465dc Don't complain about usernames that end in '$' which may be needed by 21 years ago
  millert 642ff1ce89 Use POSIX chown semantics (user:group); noted by Leandro Costa 22 years ago
  millert 8736cb4dab put bin dirs before sbin dirs in PATH for consistency with other cron scripts 22 years ago
  henning e07978f161 writeable -> writable; torh at bogus dot net 22 years ago
  pvalchev 35165da9c8 check account expiration time as well; from hamajima@nagoya.ydc.co.jp pr2835 22 years ago
  jcs 0b40d89296 don't complain about our new usernames that start with underscores 22 years ago
  millert 8596724be4 Check for S/Key entries in /etc/skey, not /etc/skeyeys; David Krause 22 years ago
  pvalchev 8f3f4efdd9 use mktemp; help & ok millert 23 years ago
  jakob 79bd272191 mtree -l (loose permissions check) on /etc/mtree/special. ok millert@. 23 years ago
  brad 90f9fa54db fix username and groupname length checks. 24 years ago
  millert 291b1c42d4 Skip entries starting with '+' in duplicate user ID check so we don't 24 years ago
  millert 678f2ac821 Don't provide diffs of sensitive files like ssh host keys. Instead, 24 years ago
  millert e2f7d1725e Add ~/.ssh/id_dsa and ~/.ssh/id_rsa to the "must be owned by user and 24 years ago
  deraadt ac223fc9c0 more fat utmp; ianm@cit.uws.edu.au 24 years ago
  todd 06e9a61dc6 gnupg ring/data ownership/permission checking added; ok millert@ 24 years ago
  marc 39a1183d94 Todd, Aaron, Dug, and me all prefer unidiff 24 years ago
  millert 95c109f653 Since sh's bulitin echo(1) supports /t and /n there is no reason to 24 years ago
  hugh ac5c85ae03 printf(1) format string fixes! checked by theo. 24 years ago
  aaron 0a2ee57885 When including the listing of a directory in root's security mail, pass the 24 years ago
  rohee f69c6ad0ce Add a little blurb explaing the meaning of mtree's output. 24 years ago
  todd c1a88d66cc fix inspired by pr 744 from karls@inet.no 24 years ago
  aaron d57c53f78c Capitalize 'id' to be consistent with our man pages. 24 years ago
  millert 71b4a7b88d sendmail support files now live in /etc/mail 25 years ago
  aaron 9f8e4d853e existance -> existence 25 years ago
  millert 8ea805fe52 match /dev/fd{0,1,2,3}{,B,C,D,E,F,G,H}[abcdefghijklmnop] when doing device checks; closes PR #750 25 years ago
  espie bad13e3a6b Give line printout along with line number. 25 years ago
  deraadt aad99d26ce make /var/backups same as mtree says; mickey 26 years ago
  millert 646731011d don't include FIFOs in check for set[ug]id files and devices; andrew@nfr.net 26 years ago
  marc 692caaedb2 better checks for . in path from "Denis A. Doroshenko" <cyxob@isl.vtu.lt> 26 years ago
  todd 4003b60995 Check a few more DOTfiles that could potentially compromise security on a per 27 years ago
  marc 0b582277ad fix ksh.kshrc; check ksh.kshrc, .kshrc for owner/mode/path 27 years ago
  millert f8b73365a5 Deal with non-existent /etc/skeykeys 27 years ago
  deraadt eadfd2f525 be more careful during termination 27 years ago
  deraadt b7fb34043d completely avoid master.passwd in the changelist processing; jbernard@tater.mines.edu 27 years ago
  deraadt 5d22791c21 handling for closed home directories; yensid@afri.imsa.edu 27 years ago
  deraadt dc14af3f0f oops, detect blowfish-a as OK; yensid@imsa.edu, PR#321 27 years ago
  deraadt 699300c397 better path handling; jbernard@tater.mines.edu, netbsd pr#3995 27 years ago
  millert 13286d26c2 /etc/profile should be checked along with .profile for consistency with 27 years ago
  flipk e64c7ac1e7 1. ignore blank lines 27 years ago