[5350] in RedHat Linux List
RedHat4.0 security
daemon@ATHENA.MIT.EDU (Chris Evans)
Wed Nov 20 20:42:03 1996
Date: Thu, 21 Nov 1996 02:43:29 +0000 (GMT)
From: Chris Evans <chris@ferret.lmh.ox.ac.uk>
To: redhat-list@redhat.com
In-Reply-To: <199611210117.UAA11331@gaffa.voicenet.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
Hi,
On my redhat4.0 system, a "find / -perm 4000" lists an awful lot of suid
programs. Some sound highly dubious. How many of these have been scrutinised
for security holes?
On other security issues, I'm far from impressed by the (default)
permissions on log files. Are we in a situation where it could be
logged publicly readable, if somone gets a failed login due to mixing
password with username? Many of the somewhat more security-oriented
config files could do with a permissions rethink too. I don't want normal
users browsing my setup. Look at it another way: there's no _valid need_
for them to be able to read them.
Finally, there was an alert to do with the wu-ftpd shipped with redhat, a
little time ago. Something to do with the realpath exploit, as well as
problems with the tar --rsh-command option, if supported by the ftp tar
binary...
Comments..?
Cheers,
Chris.
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null