Security question - uids of 0

Volker Kindermann ml at ps102.de
Mon Aug 16 08:01:48 PDT 2004


Hi James,


> The following appeared in my latest daily security run output:
> 
> 	Checking for uids of 0:
> 	root 0
> 	toor 0
> 
> This is the first time I've seen this message.
> 
> I checked /etc/passwd and found this:
> 
> 	root:*:0:0:Charlie &:/root:/bin/csh
> 	toor:*:0:0:Bourne-again Superuser:/root:
> 
> I am running FreeBSD 4.10 as a gateway/router/firewall with IPFW for a
> small home LAN.  
> 
> I ran ps -aux and looked for any processes owned by "toor" but didn't
> find any.

did you install bash? Normally, the bash from ports or packages will
install the "toor" account so you don't have to change root's shell.

If you installed bash then there's nothing to worry about this entry.
If you don't need it, just use vipw and delete it.

 -volker


More information about the freebsd-questions mailing list