看板FB_security
標 題Re: Call for review: restricted hardlinks.
發信站NCTU CSIE FreeBSD Server (Tue Mar 9 09:18:14 2004)
轉信站ptt!FreeBSD.csie.NCTU!not-for-mail
--XZq0mbLCR4KNTYFe
Content-Type: text/plain; charset=iso-8859-2
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Tue, Mar 09, 2004 at 09:16:39AM +0100, C=E9dric Devillers wrote:
+> If you create several partition ( /var /usr /home ), this problem is
+> resolved. Generally, in /usr, there are no directory write-able for all.
+> If you have a partition for /usr, no hard link to a set-uid binary ( in
+> the /usr tree ) is possible.
Believe me, I'm aware of this.
This "issue" can be used to other purposes as well.
% ln /home/<user>/important_file ~/i_cannot_read_it_now_but_maybe_some_day=
_i_will_compromise_this_machine
Anyway, it is turned off by default and there is no need to use it at all.
--=20
Pawel Jakub Dawidek
http://www.FreeBSD.org
[email protected] http://garage.freebsd.pl
FreeBSD committer Am I Evil? Yes, I Am!
--XZq0mbLCR4KNTYFe
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)
iD8DBQFATYz9ForvXbEpPzQRAmWhAJ0UHofH3RoHMhXxVvoHLplnlItl3QCgyBa9
jBzsxmWkpUEi4biC3Lipp1Q=
=2CeU
-----END PGP SIGNATURE-----
--XZq0mbLCR4KNTYFe--