[13231] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Symlinks and Cryogenic Sleep

daemon@ATHENA.MIT.EDU (Olaf Kirch)
Wed Jan 5 12:35:14 2000

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Message-Id:  <20000104231207.A11236@monad.swb.de>
Date:         Tue, 4 Jan 2000 23:12:07 +0100
Reply-To: Olaf Kirch <okir@MONAD.SWB.DE>
From: Olaf Kirch <okir@MONAD.SWB.DE>
X-To:         "Mark A. Heilpern" <heilpern@MINDSPRING.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <4.2.0.58.20000103173034.00a3c8f0@mail.mindspring.com>; from
              heilpern@MINDSPRING.COM on Mon, Jan 03, 2000 at 05:34:45PM -0500

On Mon, Jan 03, 2000 at 05:34:45PM -0500, Mark A. Heilpern wrote:
> Maybe I'm just naive, but it's my understanding that you cannot send signals
> to a process you don't own unless you are root.

That's not true for setuid processes. You're allowed to signal a process
if _either_ the effective or the real uid match. Try running passwd in
one window, in another type killall -STOP passwd.

Olaf
--
Olaf Kirch         |  --- o --- Nous sommes du soleil we love when we play
okir@monad.swb.de  |    / | \   sol.dhoop.naytheet.ah kin.ir.samse.qurax
okir@caldera.de    +-------------------- Why Not?! -----------------------
         UNIX, n.: Spanish manufacturer of fire extinguishers.

home help back first fref pref prev next nref lref last post