[8778] in bugtraq
Re: Why you should avoid world-writable directories
daemon@ATHENA.MIT.EDU (Gonzo Granzeau)
Tue Dec 22 16:02:25 1998
Mail-Followup-To: Bugtraq List <BUGTRAQ@netspace.org>
Date: Tue, 22 Dec 1998 10:51:36 -0800
Reply-To: Bugtraq List <BUGTRAQ@NETSPACE.ORG>
From: Gonzo Granzeau <gonzo@IRONMAN.PLANETQUAKE.COM>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <19981222002021.16541.qmail@cr.yp.to>; from D. J. Bernstein on
Tue, Dec 22, 1998 at 12:20:21AM -0000
As noted from previous sendmail issues, two of the stated problems can be
solved by doing a correct disk structure. You cannot create hard links across
across different partitions. That way, if you have a /, /usr, /tmp, and a
/home, you should be okay if it drops it in tmp. You'd basically have to
give their program it's own file system. This still doesn't change the fact
that it is flawed, but if you are forced to use it...
What's really funny is how often programs with 'secure' in the title usually
have a few more security problems than normal... `8r)
gonzo
--
Gonzo Granzeau > Nothing the god of biomechanics
gonzo@ironman.planetquake.com < won't let you into heaven for..
God, root, what's the difference...> -Roy Batty, _Blade Runner_