Re: securety related question...

[email protected]
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Tue, 8 Oct 2002, Bill maltby - LFS Related wrote:

> > Or... one would think after all these years you'd realize there's nothing
> > particularly wrong with being able to do this.
>
> After all these years, what I have realized is that these systems are
> *intended* for users to accomplish productive work, reliably and with
> confidence (their bad) in the working environment and results.
>
> > The current working directory is at best, just an environmental
> > variable.
>
> Nope. Inside a program (C for example), you can open a file without
> referencing any environmental variable. If it is a file that is in the
> "current working directory" of the program, no leading path is needed.
> So, that means that when the system call is made to open a file, something
> in the kernel "knows" where that process is "at". As example, think of
> fuser. It does not have access to the environment of the processes that
> are using a resource, yet it can tell you what process is using that
> resource. As I said in another post (IIRC), there is a control block that
> contains the information.

OKay, since you're going to nitpick, I'll rephrase that statement...

The current working directory, at best, has the same power as an
environmental variable.

> > If you're actually _using_ some of those inodes at the time they're
> > delinked, they won't immediately go away.  Open an flock() like you're
> > supposed to if you'd like to keep files around--user error is not a
> > bug.
>
> Good. You have solved the problem of noobs. Nobody can be just a plain old
> user on *IX. They must now all be expert C programmers. This will allow
> them to do the normal things that users are supposed to be able to do with
> some confidence that the environment they were told to expect will really
> exist for the duration of their activities.

Where exactly did you read that UNIX promises users that the sysadmin or
someone logging in with their account can't delete all their files right
out from under them at any time?

They have _every_ confidence that their files will remain on the system
until such time as they (or someone else with the proper privs should)
choose to delete them.  It's part of that whole Availability thing from
the CIA acronym (since you lectured me like a Novell admin, now I'm
returning the favor--although in this case it appears entirely necessary)
that the system shouldn't just up and randomly delete files.

I suppose if you're having other users delete your directories quite
often, that it might be a sign that you should listen to people who've
actually made a career of computer security.  ...or you can call around to
press agencies and places like CMU and tell them about this new DoS
vulnerability you've discovered in bash and make a complete ass of
yourself like Steve Gibson is so fond of doing.  I can promise you that
I'll be mightily entertained if you do.

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.