Path: utzoo!utgpu!watmath!clyde!bellcore!texbell!killer!sulaco!allen From: allen@sulaco.UUCP (Allen Gwinn) Newsgroups: news.sysadmin Subject: Re: How to stop future viruses. Summary: /etc/shadow ...shadow password file Message-ID: <331@sulaco.UUCP> Date: 10 Nov 88 03:31:19 GMT References: <16722@agate.BERKELEY.EDU> <5420@saturn.ucsc.edu> Organization: SULACO, Dallas, TX Lines: 17 In article <5420@saturn.ucsc.edu>, koreth@ssyx.ucsc.edu (Steven Grimm) writes: > In article <16722@agate.BERKELEY.EDU> greg@math.Berkeley.EDU (Greg) writes: > >On most Unix systems that I've seen, /etc/passwd is publicly readable. > >There is no reason for this. > > Unless you're proposing adding another file with usernames and uids, /bin/ls > will stop telling you who owns files if /etc/passwd isn't readable... As a matter of fact, the next release of System V has a "shadow" password file to complement /etc/passwd. It is not readable by the world. The passwords in /etc/passwd are dummies (the string ":np:" or whatever the password was in /etc/passwd prior to conversion). Should put an end to password hacking as we know it :-) -- Allen Gwinn ...sulaco!allen Disclaimer: The facts stated are my own. "Remember, facts are stupid things." - Brad Schoening (uiucdcs!schoenin)