home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!moe.ksu.ksu.edu!math.ksu.edu!deadend
- From: tar@math.ksu.edu (Tim Ramsey)
- Newsgroups: comp.security.misc
- Subject: Re: root-owned world-writable files
- Date: 21 Jul 1992 16:00:16 -0500
- Organization: Dept. of Mathematics, Kansas State University
- Lines: 13
- Message-ID: <14htt0INNiep@hilbert.math.ksu.edu>
- References: <62524@cup.portal.com> <1992Jul21.201056.662@newshost.lanl.gov>
- NNTP-Posting-Host: hilbert.math.ksu.edu
-
- jfowler@beta.lanl.gov (John C. Fowler) writes:
-
- >Only if the system trusts the contents of the file, or root executes it,
-
- How do you get a complete list of files that are trusted by root, or by
- programs that root trusts (that is, are setuid root)?
-
- Much easier to simply not have world-writable files owned by root.
-
- --
- Tim Ramsey, 913.532.6750
- Department of Mathematics
- Kansas State University
-