home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.os.vms
- Path: sparky!uunet!gatech!darwin.sura.net!jhunix.hcf.jhu.edu!jhuvms.hcf.jhu.edu!ecf_stbo
- From: ecf_stbo@jhuvms.hcf.jhu.edu (Remember Grimalkin)
- Subject: Re: HELP!!! Security problem for gurus. [Directories]
- Message-ID: <4JAN199310390710@jhuvms.hcf.jhu.edu>
- News-Software: VAX/VMS VNEWS 1.41
- Sender: news@jhunix.hcf.jhu.edu (JHU News Administrator)
- Organization: The Johns Hopkins University - HCF
- References: <1i6dd2INNrct@gap.caltech.edu>,<14628002@zl2tnm.gen.nz> <1i904kINNdbj@gap.caltech.edu>
- Date: Mon, 4 Jan 1993 15:39:00 GMT
- Lines: 17
-
- In article <1i904kINNdbj@gap.caltech.edu>, carl@SOL1.GPS.CALTECH.EDU writes...
- >Well, I don't have the listings at hand, but, let's suppose: RMS gets damaged
- >in such a way that when JOE_USER logs in, when RMS looks up the rightslist
- >identifiers he holds (part of loginout), it misreads RIGHTSLIST.DAT in such a
- >way as to assign him an identifier we'd created to allow someone to modify,
- >say, SYSTARTUP_V5.COM?
-
- RMS would call the XQP would do rightslist and other protection checking. You
- can't bypass ACL checking by doing file i/o with $qio. I would be more worried
- about its handling of global buffers, if you want to talk about how a hosed RMS
- used by one user could affect the whole system. I realize this is picky, but
- what the hell.
-
- Tom O'Toole - ecf_stbo@jhuvms.hcf.jhu.edu - JHUVMS system programmer
- Homewood Computing Facilities, Johns Hopkins University, Balto. Md. 21218
- >Here comes a jet ski.
- >weuh weeuhh weeuhh weeuhh WEEUHH WEEUHH WEEUHH WEEUHH weeuhh weeuhh weeuhh weuh
-