[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] All folders visable on whole server



> > As far as reading stuff, I've been on plenty of servers where I could
move
> > right up through the ftp tree until I was at the very root of the server
> > (/), and I could download stuff and read it.
>
> That's major scary stuff.... any decent perl user could download your
shadow
> file and get the root/admin password.
>
> Kevin

Kevin,
I'm a bit confused here. Do you mean the /etc/passwd and /etc/passwd- files?
Because I look in those two files and while I do see all of the users on the
site, I don't see anything that resembles a password or even an encrypted
version of the password.

Am I looking at the wrong passwd file?

Carrie Bartkowiak