Ftp-WG: in mlst-16, chmod bypass, we deprecate which?
Pat LaVarre <[email protected]> Wed, 2 Oct 2002 16:00:50 -0500
| Newsgroups | gmane.ietf.ftpext |
|---|---|
| Message-ID | <[email protected]> |
> Subject: Ftp-WG: to mlst-16 from mlst-15 ftp://munnari.oz.au/internet-drafts/draft-ietf-ftpext-mlst-16.txt.gz > = 11. Security Considerations > ... > + Server FTP should take care not to reveal > + sensitive information about files to unauthorised > + parties. In particular, some underlying > + filesystems provide a file identifier which, if > + known, can allow many of the filesystem protection > + mechanisms to be by-passed. That identifier would > + not be a suitable choice to use as the basis of > + the value of the unique fact. Would a classic Unix inode number be an example of an identifier that lends itself to abuse, or did we have something else in mind? Curiously yours, thanks in advance, Pat LaVarre __________________________________________________ Do you Yahoo!? New DSL Internet Access from SBC & Yahoo! http://sbc.yahoo.com