Re: hardlinks to setuid binaries
Michael Richardson <[email protected]> Thu, 31 Mar 2022 12:58:02 -0400
| Newsgroups | gmane.os.netbsd.devel.security |
|---|---|
| Message-ID | <19821.1648745882@localhost> |
--=-=-= Content-Type: text/plain George Georgalis <[email protected]> wrote: > However, an audit of package hardlink count, warning on check, > block on upgrade (without --force), to facilitate finding extra links, > seems like a low cost sanity check? It sure seems like it's the upgrade process that needs to care to remove "old" suid bits on old executables. Or alternatively, overwrite them without changing the inode. It's a tussle as to which is better. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works | IoT architect [ ] [email protected] http://www.sandelman.ca/ | ruby on rails [ --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmJF3ZoACgkQgItw+93Q 3WVDiggAgiU82Fqd7f0XAcaIKou0rrVnl7pdpawHQF1icWRUGfdpHne0htna0Msb E6o1fRzq8cLMHhz6fi/Iofa4i3FU50p3An4WWbJFk98J+hksYa+a8IInyAxxBqd5 rf78Q4ptw+4moDSL3WObJwmjaYK06K0Y4U2cy2x/kMdE8gYK3Bf7LCSdtsptlAKo R4qfbSv0OuJao/mxEMqIkZQV23lm3khB4JmBd4yfxyDZo0iv2AdiC7dLQR0rdIKz kgvrJKK02px6ZsDKlElrGnZd55OZYL6sZN6h16x5cMyrLFaL1UBUF/XW5dkEhPjB bbyUA+hQWIun6mJ2UeCsR1Cn7IIlow== =Arth -----END PGP SIGNATURE----- --=-=-=--