[6264] in RedHat Linux List
Re: More redhat-4.0 security
daemon@ATHENA.MIT.EDU (Kyle Ferrio)
Tue Nov 26 14:54:00 1996
Date: Tue, 26 Nov 1996 14:35:35 -0500 (EST)
From: Kyle Ferrio <kbf@phy.duke.edu>
To: redhat-list@redhat.com
In-Reply-To: <Pine.LNX.3.95.961126175042.29473A-100000@ferret.lmh.ox.ac.uk>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
On Tue, 26 Nov 1996, Chris Evans wrote:
> Hi, a minor point this time (in my "RedHat security drive"), but
> /usr/local/bin appears before /bin,/usr/bin, etc. in my path.
>
> Whereas I certainly don't, some sites allow people to install their own
> binaries/other stuff under /usr/local. This might open up trojan
> possibilities.
>
> Chris.
Doesn't a site that gives normal users write privliges on /usr/local/bin
deserve whatever happens, good or bad? This seems like a really bad plan.
A better approach might be to create a (small) group for trusted
maintainers of local packages, and chown /usr/local/bin to them. [This is
more flexibly done with afs acls than plain unix, of course.] But the
general idea is that if a lot of users need a binary, someone trustworthy
should volunteer to maintain it. If a binary isn't needed by a lot of
users, it probably doesn't belong in /usr/local/bin. This is arguable, to
be sure.
Kyle Ferrio kbf@phy.duke.edu
Duke University, Dept. of Physics (919) 660-2518 office
Box 90305, Durham N.C. 27708-0305, USA (919) 660-2525 FAX
PGP fingerprint = 52 5F 5F 90 AE BD BF 5D 14 FD 20 7D 20 E0 30 59
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null