delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2005/06/07/08:32:44

Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
Date: Tue, 7 Jun 2005 14:31:25 +0200
From: Corinna Vinschen <corinna-cygwin AT cygwin DOT com>
To: cygwin AT cygwin DOT com
Subject: Re: Login & Something diff since cygwin 1.5.15-1 release - could it be security changes that were made
Message-ID: <20050607123125.GE23172@calimero.vinschen.de>
Reply-To: cygwin AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
References: <VA DOT 000011ab DOT 0053f8b1 AT thesoftwaresource DOT com> <20050606104023 DOT GG3268 AT calimero DOT vinschen DOT de> <VA DOT 000011af DOT 013e5ade AT thesoftwaresource DOT com>
Mime-Version: 1.0
In-Reply-To: <VA.000011af.013e5ade@thesoftwaresource.com>
User-Agent: Mutt/1.4.2i

On Jun  6 17:02, Brian Keener wrote:
> Thanks for the response.  1.5.17 doesn't correct it either. I have tried each
> release since 1.5.14 and and always end up rolling back to 1.5.14.

I realized you're using W2K and now I'm mildly confused.

I just tried it on W2K and I'm unable to use login on the command line.
This is not actually a surprise, since the function which is used to get
a logon token, LogonUser, requires a user privilege (SeTcbPrivilege),
which isn't held by any user other than SYSTEM.  This requirement has been
dropped in XP and 2K3, but it's required on 2K and, AFAIK, on NT4.

The result should be that login always fails on the command line, unless
you gave the SeTcbPrivilege to your account, which, btw, is not a good
idea.

I'm confused, because this should not have change between 1.5.14 and 1.5.15
and when I try this with 1.5.14, login still fails for me, as I'd expect.
What I don't get is, why this works for you with 1.5.14 and before.

Can you please revert to 1.5.14, call `strace -o log.out login briank',
login, and send the log.out file to this list?  But please, be careful!
The log file will contain your password at one point,m in a line with
the word "LogonUserA".  Overwrite it with some random string before
sending the file content to this list.


Thanks,
Corinna

-- 
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Project Co-Leader          mailto:cygwin AT cygwin DOT com
Red Hat, Inc.

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019