|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: BUGTRAQ ALERT: Solaris 2.x vulnerability
Patrick Hess (phess
best.com)Wed, 16 Aug 1995 12:03:52 -0700
- Messages sorted by: [ date ][ thread ][ subject ][ author ]
- Next message: Neil Readwin: "Re: BUGTRAQ ALERT: Solaris 2.x vulnerability"
- Previous message: Alexander L. Haiut: "Re: BUGTRAQ ALERT: Solaris 2.x vulnerability"
- In reply to: Nathan Lawson: "Re: BUGTRAQ ALERT: Solaris 2.x vulnerability"
- Next in thread: (no name): "personalized /tmp (was: BUGTRAQ ALERT: Solarix 2.x vulnerability)"
"Nathan Lawson once said:"
>
> Aleph1 said:
> > Well while we taling about SysV ps IRIX's its sgid to sys, writes
> > to /tmp/.ps_data and /tmp/.ps_XXXXXX but /tmp was the sticky bit on.
>
> The /tmp/.psXXXXXX is open to a race. The directory is safe as long as it
> isn't world writable.
>
> -Nate
>
Ya know, if /tmp isn't world writeable doesn't that defeat the purpose of
having a /tmp at all? It's kinda like security by never giving out
accounts. Sure, it's secure but useless. The whole point of having a /tmp
is to give people with limited disk space somewhere to put their junk for a
short time. That means the _world_ has to be able to write to it. The
sticky-bit on the directory makes it such that only the creator of the file
can remove it when the directory is otherwise world writeable. It is the
obvious and elegant solution to this problem.
Sorry for the little tirade, but I kinda got the impression that there were
people on this list that didn't quite understand why this hole is serious,
but easily fixed. I now return you to your regularly scheduled security
leaks.
Pat
- Next message: Neil Readwin: "Re: BUGTRAQ ALERT: Solaris 2.x vulnerability"
- Previous message: Alexander L. Haiut: "Re: BUGTRAQ ALERT: Solaris 2.x vulnerability"
- In reply to: Nathan Lawson: "Re: BUGTRAQ ALERT: Solaris 2.x vulnerability"
- Next in thread: (no name): "personalized /tmp (was: BUGTRAQ ALERT: Solarix 2.x vulnerability)"