[5533] in bugtraq

home help back first fref pref prev next nref lref last post

Re: xbru vulnerability

daemon@ATHENA.MIT.EDU (Theo Van Dinter)
Sat Nov 8 19:32:56 1997

Date: 	Sat, 8 Nov 1997 13:15:58 -0500
Reply-To: Theo Van Dinter <felicity@KLUGE.NET>
From: Theo Van Dinter <felicity@KLUGE.NET>
X-To:         Kyle Amon <amonk@GNUTEC.COM>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <199711080559.AAA23651@minotaur.gnutec.com>

On Sat, 8 Nov 1997, Kyle Amon wrote:

| > It appears as though the program was NOT suppose to go out 777 -- rather
| > 1777.  That little sticky bit of a difference provides for the security of
| > ownership.  Thank you for bringing this to our attention.

Unless you want non-root users to do restores/backups, there's no problem in
making the perms non-world writeable.  My /usr/local/lib/bru directory is
775, works fine (as expected) from root.


--
Randomly Generated Tagline:
Just a hunch; Murphy was an optimist.

home help back first fref pref prev next nref lref last post