home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!wupost!sdd.hp.com!elroy.jpl.nasa.gov!jato!dave
- From: dave@jato.jpl.nasa.gov (Dave Hayes)
- Subject: Re: root-owned world-writable files
- Message-ID: <1992Jul21.205850.21907@jato.jpl.nasa.gov>
- Reply-To: dave@jato.jpl.nasa.gov
- Organization: Jet Propulsion Lab - Pasadena, CA
- References: <62524@cup.portal.com>
- Date: Tue, 21 Jul 1992 20:58:50 GMT
- Lines: 15
-
- VESOFT@cup.portal.com (Michael D Hensley) writes:
- >Agree/disagree/discussion: Any root-owned world-writable file should be
- >considered a potential security loophole.
-
- Only if it can somehow be executed OR it is something that a current
- executable references as trusted information.
-
- One can also ask: "Is it really necessary to have a world writable file
- owned by root?"
-
- --
- Dave Hayes - Network & Communications Engineering - JPL / NASA - Pasadena CA
- dave@elxr.jpl.nasa.gov dave@jato.jpl.nasa.gov ...usc!elroy!dxh
-
- There is no greater calamity for a nation or individual
- than not finding contentment in one's sufficiency.
-