OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Manuel Bouyer (bouyerantioche.lip6.fr)
Date: Mon Jan 15 2001 - 15:01:48 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Mon, Jan 15, 2001 at 04:56:30PM +0100, Emmanuel Dreyfus wrote:
    > When running ktrace as root, the ktrace.out file is created according to
    > root's umask. Don't you think it would be better to force that file to
    > mode 600?
    >
    > As it is today, a negligent system administrator can leave a
    > world-readable ktrace.out file in the filesystem, and this file might
    > contain sensitive information
    >
    > Opinions?

    Yes, that would be a good idea. I can't see a situation where a user would want
    to read the ktrace.out of someone else (and don't have root access or passwd
    do su).

    --
    Manuel Bouyer <bouyerantioche.eu.org>
    --