local security issue with dar during archive restoration

Denis Corbin <[email protected]> Sat, 12 Feb 2005 23:05:20 +0100
Newsgroups gmane.comp.sysutils.backup.dar.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

When restoring an archive, the permission of directory and subdirectory
where is located the file being processed are changed to allow the
creation of a new entry in the directory. The permission is set back to
original value when the directory/sub-directory has been completely
processed. This temporary permission allows anyone to create and remove
an entry in the directory.

As you can see, the outer-most directory will have proper permission set
back at the end of the restoration, thus during all the backup process
an ordinarily unauthorized user may perform "unauthorized" action in
this directory (remove, create or replace any file), this extends to
sub-directory but for a shorter period of time. Such action (file
replacement by non-privileged user) will however let some traces like
ownership changes.

For those working in a 'hostile' multi-user environment and wishing to
perform restoration in multi-user runlevel, a fix is available in CVS
under the branch_2_2_x tag. It will be included in the soon to come
release 2.2.1.

Cheers,
Denis.

P.S.: follow-up to dar-discussion mailing-list, if necessary.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFCDn2fpC5CI8gYGlIRAmXGAJ9kmKry+5/SaessmKLAWSXAZOX6oQCgiHjo
CBFOLoNl8HRYe1y1Ws/H6Bg=
=PfjK
-----END PGP SIGNATURE-----


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click