Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign updoas always works, even with wrong password #2
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment
Hide comment
|
Fixed in latest commit. |
slicer69
closed this
Jun 24, 2016
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
slicer69 commentedJun 24, 2016
I have found that the latest snapshot of doas always succeeds for any permitted user in the doas.conf file, even when the wrong password has been provided. This means any user listed with "permit" in the doas file can run any command granted to them, even if they provide the wrong password.