02-20-2008
3,
0
Join Date: Feb 2008
Last Activity: 20 February 2008, 6:04 PM EST
Posts: 3
Thanks Given: 0
Thanked 0 Times in 0 Posts
su mistery
Hi All,
Today I was logged in with my username (non root) on one of our Solaris 9 boxes and and typed "su - appserver".
The strange thing is that I was not prompted for appserver's password and it allowed me to become "appserver" even if I am not root.
Can anyone suggest where to look for problems as this appears to be a big security issue.
Cheers,
Midraga