Skip to content

Users conflicts #4

@Mazamazine

Description

@Mazamazine

Users created under alternc are under /var/lib/extrausers/.
In nsswitch.conf though, it's looking first in /etc/{shadow,passwd,group}

The result of this is having conflicts between alternC users and existing users, leading to security problems.

Using alternc-php-fpm for instance, we can see processes under the right user but with the wrong uid.
Say you have your admin user in alternc (uid 2000) and an admin user with a uid 10440, here is what you get:
10440 5768 0.0 0.8 275752 18176 ? S 18:03 0:00 \_ php-fpm: pool admin

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions