OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 3rd quarter (Jul-Sep) 1998: Re: Verity/Search'97 Security Problems

Re: Verity/Search'97 Security Problems

Jay Soffian (jayCIMEDIA.COM)
Thu, 16 Jul 1998 17:28:47 -0400

Last message, I promise. My brain isn't working today. suid (or sgid)
is a terrible idea. Using something other than '.orig' works, but
that's security by obscurity. Probably, you are best using a <files>
section (or equiv if not Apache) to protect the '.orig' binaries.

j.
--
Jay Soffian <jaycimedia.com>                       UNIX Systems Administrator
404.572.1941                                             Cox Interactive Media