OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: /proc filesystem allows bypassing directory permissions on

From: Dan Yefimov (danlightwave.net.ru)
Date: Tue Nov 03 2009 - 07:06:00 CST


On 03.11.2009 2:33, Martin Rex wrote:
> Doing it for a socket might be a bad idea -- and usually impossible,
> one cannot undo the shutdown(SHUT_WR) of a socket...
>
Nobody will ever need that, since sockets are bidirectional and their file
descriptors are in fact both readable and writable. But changing access mode of
regular and special files, directories and even pipes file descriptors is in
fact possible and could be accomplished rather easily by checking the
corresponding inode (this is true at least for Linux).
--

Sincerely Your, Dan.