[cvsnt] Re: Possible security risk

River river at ptt.yu
Fri Jun 13 16:26:14 BST 2003


Community technical support mailing list was retired 2010 and replaced with a professional technical support team. For assistance please contact: Pre-sales Technical support via email to sales@march-hare.com.


No the other user do not exist on machine hosting CVSNT either on local
machine. I forgot to mention that I am using pserver authentication, without
maping any user to existing accounts.

And when I try to add new user with the other (no admin) user I got, as
espected, message that only administrators can add or change user accounts.
But when I try to delete it alowes me????

I think that this is some sort of bug. Am I wrong ????
"Tony Hoyle" <tmh at nodomain.org> wrote in message
news:bcb86g$k7e$1 at sisko.nodomain.org...
> River wrote:
>
> > With cvsnt 2.0.4  hosted on network I created 2 user accounts. One of
them
> > is added to admin file, and other is not. But when I logged with not
admin
> > account I was able to delete administrator account using passwd
> > subcommand. Anyoune ???
> > River
>
> Presumably the other user was an administrator on the machine (either a
> domain admin or a local admin on the cvs box).
>
> Tony
>




More information about the cvsnt mailing list
Download the latest CVSNT, TortosieCVS, WinCVS etc. for Windows 8 etc.
@CVSNT on Twitter   CVSNT on Facebook