[8778] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Why you should avoid world-writable directories

daemon@ATHENA.MIT.EDU (Gonzo Granzeau)
Tue Dec 22 16:02:25 1998

Mail-Followup-To: Bugtraq List <BUGTRAQ@netspace.org>
Date: 	Tue, 22 Dec 1998 10:51:36 -0800
Reply-To: Bugtraq List <BUGTRAQ@NETSPACE.ORG>
From: Gonzo Granzeau <gonzo@IRONMAN.PLANETQUAKE.COM>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <19981222002021.16541.qmail@cr.yp.to>; from D. J. Bernstein on
              Tue, Dec 22, 1998 at 12:20:21AM -0000

As noted from previous sendmail issues, two of the stated problems can be
solved by doing a correct disk structure.  You cannot create hard links across
across different partitions.  That way, if you have a /, /usr, /tmp, and a
/home, you should be okay if it drops it in tmp.  You'd basically have to
give their program it's own file system.  This still doesn't change the fact
that it is flawed, but if you are forced to use it...

What's really funny is how often programs with 'secure' in the title usually
have a few more security problems than normal... `8r)

gonzo
--
Gonzo Granzeau                     >  Nothing the god of biomechanics
gonzo@ironman.planetquake.com      <  won't let you into heaven for..
God, root, what's the difference...>       -Roy Batty, _Blade Runner_

home help back first fref pref prev next nref lref last post