Re: scary, maybe

Sam Halliday <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Matthias Benkmann wrote:
>> echo "The folders /tmp /tmp/.font-unix /tmp/.X11-unix /var/mail
>/var/tmp> are supposed to be globally writable"
>That is not completely correct. They need to have the sticky flag
>(o+t), too, otherwise it's a security hole. You should add a test for
>this to your script. 

yeah, youre completely correct, i should have checked for that also in
the directory check! but it still finds vulnerable files and other
directories... i have not done anything out of the ordinary on my
system, but there were, to my surprise, a few files which somehow got
installed group writable! (man/info pages mostly). i seen this as a big
hole as you could easily perform a DoS attack on a hard disk by doing
something like catting /dev/random to a file until the physical space is
all used up.

cheers,
Sam
-- 
Punning is the worst vice, and there's no vice versa.
-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.