Ftp-WG: in mlst-16, chmod bypass, we deprecate which?

Pat LaVarre <[email protected]> Wed, 2 Oct 2002 16:00:50 -0500
Newsgroups gmane.ietf.ftpext
Message-ID <[email protected]>
> Subject: Ftp-WG: to mlst-16 from mlst-15

ftp://munnari.oz.au/internet-drafts/draft-ietf-ftpext-mlst-16.txt.gz

> = 11. Security Considerations
> ...
> + Server FTP should take care not to reveal
> + sensitive information about files to unauthorised
> + parties.  In particular, some underlying
> + filesystems provide a file identifier which, if
> + known, can allow many of the filesystem protection
> + mechanisms to be by-passed. That identifier would
> + not be a suitable choice to use as the basis of
> + the value of the unique fact.

Would a classic Unix inode number be an example of an
identifier that lends itself to abuse, or did we have
something else in mind?

Curiously yours, thanks in advance, Pat LaVarre

__________________________________________________
Do you Yahoo!?
New DSL Internet Access from SBC & Yahoo!
http://sbc.yahoo.com