Re: scary, maybe
Sam Halliday <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
Matthias Benkmann wrote: >> echo "The folders /tmp /tmp/.font-unix /tmp/.X11-unix /var/mail >/var/tmp> are supposed to be globally writable" >That is not completely correct. They need to have the sticky flag >(o+t), too, otherwise it's a security hole. You should add a test for >this to your script. yeah, youre completely correct, i should have checked for that also in the directory check! but it still finds vulnerable files and other directories... i have not done anything out of the ordinary on my system, but there were, to my surprise, a few files which somehow got installed group writable! (man/info pages mostly). i seen this as a big hole as you could easily perform a DoS attack on a hard disk by doing something like catting /dev/random to a file until the physical space is all used up. cheers, Sam -- Punning is the worst vice, and there's no vice versa. -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message