Re: [rfc] change default setuid permissions from 4755 to 4711

Tomasz Kłoczko <[email protected]> Wed, 3 Aug 2005 12:26:42 +0200 (CEST)
Newsgroups gmane.linux.pld.shadow.general
Message-ID <[email protected]>
On Tue, 2 Aug 2005, Mike Frysinger wrote:

> we've been patching the permissions in shadow for a while now from 4755 to
> 4711 ... i dont think anyone here has asked the shadow maintainers, so i'm
> doing so now :)
>
> there's no need to grant read permissions for setuid binaries, so 4711 is just
> as functional as 4755, while keeping internal binary information (such as
> function addresses) hidden

Q: do you know what is it SbO (Security by Obscurity) ?
If you don't go ahead and learn something about this ..

Hint: if for example one of shadow setuid tools will have known security 
bug. How do think .. how many seconds intruder will stop for checkin is 
attacked binary is readable or not ? (before runing exploit) and/or is
in this case removing read atrubutes will help or not ?

kloczek
-- 
-----------------------------------------------------------
*Ludzie nie majÂą problemĂłw, tylko sobie sami je stwarzajÂą*
-----------------------------------------------------------
Tomasz KÂłoczko, sys adm @zie.pg.gda.pl|*e-mail: [email protected]*