Age | Commit message (Collapse) | Author | |
---|---|---|---|
2002-07-23 | check account expiration time as well; from hamajima@nagoya.ydc.co.jp pr2835 | Peter Valchev | |
2002-07-17 | don't complain about our new usernames that start with underscores | joshua stein | |
deraadt and millert ok | |||
2002-05-22 | Check for S/Key entries in /etc/skey, not /etc/skeyeys; David Krause | Todd C. Miller | |
We could use skeyinfo(1) to check but this is much cheaper. | |||
2002-02-18 | use mktemp; help & ok millert | Peter Valchev | |
2001-10-01 | mtree -l (loose permissions check) on /etc/mtree/special. ok millert@. | Jakob Schlyter | |
2001-04-06 | fix username and groupname length checks. | Brad Smith | |
-- Patch from: wilfried@ via PR#1761 Ok'd by: deraadt@ | |||
2001-04-05 | Skip entries starting with '+' in duplicate user ID check so we don't | Todd C. Miller | |
get false positives for YP stuff. Closes PR 1755 | |||
2001-03-25 | Don't provide diffs of sensitive files like ssh host keys. Instead, | Todd C. Miller | |
just save the md5 checksums so we can still determine when something change. Entries in /etc/changelist that are prefixed with a '+' will only have their md5 checksums saved, not the actual files. | |||
2001-03-16 | Add ~/.ssh/id_dsa and ~/.ssh/id_rsa to the "must be owned by user and | Todd C. Miller | |
not readable by other" block. Remove ~/.ssh/random_seed as it is not used in OpenSSH. Add ~/.ssh/authorized_keys2, and ~/.ssh/known_hosts to the "must be owned by user and not writable" block. | |||
2001-01-31 | more fat utmp; ianm@cit.uws.edu.au | Theo de Raadt | |
2000-12-22 | gnupg ring/data ownership/permission checking added; ok millert@ | Todd T. Fries | |
2000-12-17 | Todd, Aaron, Dug, and me all prefer unidiff | Marco S Hyman | |
2000-10-20 | Since sh's bulitin echo(1) supports /t and /n there is no reason to | Todd C. Miller | |
use printf(1) here. This way there is no possibility of format string problems and we use a shell builtin instead of an external command. | |||
2000-10-18 | printf(1) format string fixes! checked by theo. | Hugh Graham | |
inspiration from dynamo@ime.net. also a typo fix. | |||
2000-10-06 | When including the listing of a directory in root's security mail, pass the | Aaron Campbell | |
-q flag to ls(1) so that non-printable characters will appear as '?'. This prevents a malicious user from fooling the administrator into thinking the contents of a file name are actually valid script output (note that you can put newlines in file names); deraadt@ ok | |||
2000-07-23 | Add a little blurb explaing the meaning of mtree's output. | Bruno Rohee | |
millert@ ok. | |||
2000-06-18 | fix inspired by pr 744 from karls@inet.no | Todd T. Fries | |
changed so files are e.g. backups/etc_passwd not backups/_etc_passwd | |||
2000-05-26 | Capitalize 'id' to be consistent with our man pages. | Aaron Campbell | |
2000-04-16 | sendmail support files now live in /etc/mail | Todd C. Miller | |
2000-02-29 | existance -> existence | Aaron Campbell | |
1999-11-22 | match /dev/fd{0,1,2,3}{,B,C,D,E,F,G,H}[abcdefghijklmnop] when doing device ↵ | Todd C. Miller | |
checks; closes PR #750 | |||
1999-06-19 | Give line printout along with line number. | Marc Espie | |
1998-11-22 | make /var/backups same as mtree says; mickey | Theo de Raadt | |
1998-08-17 | don't include FIFOs in check for set[ug]id files and devices; andrew@nfr.net | Todd C. Miller | |
1998-07-11 | better checks for . in path from "Denis A. Doroshenko" <cyxob@isl.vtu.lt> | Marco S Hyman | |
1998-05-10 | Check a few more DOTfiles that could potentially compromise security on a per | Todd T. Fries | |
user basis. | |||
1998-03-22 | fix ksh.kshrc; check ksh.kshrc, .kshrc for owner/mode/path | Marco S Hyman | |
1998-02-25 | Deal with non-existent /etc/skeykeys | Todd C. Miller | |
1997-12-28 | be more careful during termination | Theo de Raadt | |
1997-11-17 | completely avoid master.passwd in the changelist processing; ↵ | Theo de Raadt | |
jbernard@tater.mines.edu | |||
1997-10-05 | handling for closed home directories; yensid@afri.imsa.edu | Theo de Raadt | |
1997-09-29 | oops, detect blowfish-a as OK; yensid@imsa.edu, PR#321 | Theo de Raadt | |
1997-09-02 | better path handling; jbernard@tater.mines.edu, netbsd pr#3995 | Theo de Raadt | |
1997-06-23 | /etc/profile should be checked along with .profile for consistency with | Todd C. Miller | |
/etc/csh.login and .login. From Chris Jones <cjones@rupert.oscs.montana.edu> | |||
1997-06-02 | 1. ignore blank lines | flipk | |
2. /-ro/ -> /^-ro$/ : allows hostnames containing "*-ro*" and ignores "-root" | |||
1997-03-17 | Don't consider an account disabled just because the password length != 13. | gene | |
Also, take into account users w/ the blowfish cypher. | |||
1996-12-10 | blow away tmp dir on more traps | Theo de Raadt | |
1996-12-06 | check for entry in /etc/skeykeys and ~/.ssh in evil system() | Todd C. Miller | |
1996-12-06 | Change some "test -f" to "test -s" | Todd C. Miller | |
Don't bitch about star'd out logins unless they have a .rhosts/.shosts/.klogin file (ie: something that would let them in via rsh/ssh). | |||
1996-12-06 | skip lines in /etc/passwd that start with + or -. | Todd C. Miller | |
don't bitch about root-owned .rhosts since multiple system accounts share root's homedir. | |||
1996-11-30 | Merged our changes back into 4.4BSD version. | Todd C. Miller | |
Can't do "find -ls" since we need to store the date in an absolute format (ls -T). Use "find -print0" | xargs -0 instead. | |||
1996-11-23 | Deal with leading whitespace in find output. Fixes problem of devices | Todd C. Miller | |
showing up in the setuid list ;-) | |||
1996-10-22 | Update to work properly with output from find -ls; also skip commented out | Thorsten Lockert | |
lines in /etc/exports | |||
1996-09-20 | names of set-uid files are no longer passed to a shell. | bitblt | |
Thanks to deraadt for pointing out the -ls flag on find. | |||
1996-09-16 | toor is gone; thanks bibtlt | Theo de Raadt | |
1996-09-15 | setup trap after mkdir | Theo de Raadt | |
1996-09-15 | kill the races; found by bitblt | Theo de Raadt | |
1996-07-19 | Would give complain that /etc/hosts.equiv /etc/shosts.equiv /etc/hosts.lpd | Todd C. Miller | |
have '+' in them even when they don't. Escaped the + to fix. | |||
1996-07-12 | setgid too | Theo de Raadt | |
1996-07-07 | only watch for pure + entries | Theo de Raadt | |