[Summary]problem with login

From: Douglas Sean Hagan (shagan@hera.wku.edu)
Date: Tue Jan 19 1999 - 09:30:51 CST

Most of the responses said that if I turned off the setuid bit on
/bin/login then this would go away. I had thought that this would do it,
but wanted to get other peoples advice on this. I turned off the setuid
bit on /bin/login and things seem to be working just fine.

Thanks to:

John Berninger <jberninger@bbtnet.com>
Nickolai Zeldovich <kolya@zepa.net>
nicholas harteau <nrh@sfx.com>
John DiMarco <jdd@cs.toronto.edu>
Casper Dik <casper@holland.Sun.COM>
James R Grinter <jrg@blodwen.demon.co.uk>

-----Original Message-----
From: Douglas Sean Hagan [SMTP:shagan@hera.wku.edu]
Sent: Friday, January 15, 1999 1:12 PM
To: sun-managers@sunmanagers.ececs.uc.edu
Subject: problems with login

We have an interesting problem/curiosity here. The machine is an E450
running Solaris 7 with all patches. We have a user that will telnet in to
the machine and once he gets in he will re run login by hand and and login
again. This is causing us problems in that it is hard to track the user.
I tried to replicate this on a Linux box and the second login process dies
with a signal 1. Has anyone else seen this in Solaris, and how can I turn
this off. We are a University and when one student knows how to do this
stuff, all of them will soon.

                                        Douglas Sean Hagan

