security review of authorise_login() requested (or an explanation :)

Luke Kenneth Casson Leighton lkcl at samba.org
Tue Feb 8 00:38:45 GMT 2000


hi, why is authorise_login() doing a check for a previously registered
guest username, and then if this succeeds, setting the guest status to
True without reinitialising any other info?

i mean, is it _ok_ to reuse user_structs like this?

yours, confused,

luke

<a href="mailto:lkcl at samba.org"   > Luke Kenneth Casson Leighton    </a>
<a href="http://www.cb1.com/~lkcl"> Samba and Network Development   </a>
<a href="http://samba.org"        > Samba Web site                  </a>
<a href="http://www.iss.net"      > Internet Security Systems, Inc. </a>
<a href="http://mcp.com"          > Macmillan Technical Publishing  </a>

 ISBN1578701503 DCE/RPC over SMB: Samba and Windows NT Domain Internals



More information about the samba-technical mailing list