in.ntalkd and in.talkd are launched from inetd.conf with
user field set to "root".
A very simple and obviously correct change can limit the
security damage a hole in either of these daemons will
In RedHat6.1, please change the "root" field to "talkd.tty".
Group tty is the only special privilege required. "talkd"
should be a new user who owns no files and has a null shell
in /etc/passwd. Don't use the overloaded user "nobody".
This should take someone about, ooh, 10 minutes :-)
------- Additional Comments From 06/17/99 21:28 -------
i believe theres also a spelling error. waut instead of wait.
Fixed in netkit-base-0.10-33.
Um, using the overloaded nobody.