This is the mail archive of the cygwin-patches@cygwin.com mailing list for the Cygwin project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: Corinna or Pierre please comment? [jason@tishler.net: Re: setuid


On Tue, Jul 23, 2002 at 10:53:47AM -0400, Pierre A. Humblet wrote:
> True, there is a way...
> I found the mail thread. It's weird that apparently he can get
> mkpasswd to work. NetUserEnum in mkpasswd SHOULD fail for the same reason
> that NetUserGetGroups is failing in get_user_groups.
> Ah, but with -d -u mkpasswd uses NetUserGetInfo, not NetUserEnum. 
> Still, it SHOULD fail too.

But it's not the same situation.  When calling mkpasswd he's
logged in as authenticated user.  When NetUserGetGroups() is called,
it's called from an account which is unknown to the domain (SYSTEM)
and so is treated as anonymous... at least it's as I understand the
situation.

Corinna

-- 
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Developer                                mailto:cygwin@cygwin.com
Red Hat, Inc.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]