Skip to main content.

2001-Aug-01

I saw a BugTraq posting about locate database exploit that can be done by nobody. I searched pilchuck and found a mailbox owned by nobody. The aliases file didn't have user nobody (like my BSD boxes have). The aliases file said it was generated by eximconfig in 1999. The newer installed eximconfig now also adds "nobody". (I see this was addressed in debian PR #59712.)

I also emailed a few comments about the "nobody" to BugTraq.