home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!darwin.sura.net!sgiblab!bridge2!news.claremont.edu!fenris!jwinstea
- From: jwinstea@fenris.claremont.edu (Jim Winstead Jr.)
- Newsgroups: comp.os.linux
- Subject: Re: rm Security Problem!
- Message-ID: <1992Nov16.182222.2055@muddcs.claremont.edu>
- Date: 16 Nov 92 18:22:22 GMT
- References: <1992Nov16.133710.20417@r-node.gts.org>
- Sender: news@muddcs.claremont.edu (The News System)
- Organization: Harvey Mudd College, WIBSTR
- Lines: 30
-
- In article <1992Nov16.133710.20417@r-node.gts.org> tfoley@r-node.gts.org (Tim Foley) writes:
- > I think I may have found a large problem with 'rm' as it comes in the
- >SLS distribution.
-
- Nope, just a problem with your understanding of how permissions are
- handled under Unix. Not an uncommon problem at all...
-
- > Logged in as *anyone* I can delete *almosy any file* with the rm
- >command, it just comes up and asks 'override mode 0600' or whatever
- >and away it goes! I was able to delete copies of my passwd and inittab
- >in the /etc dir using the guest login....very annoying, now disabled!
-
- When you go to delete a file, it really doesn't matter what the
- permissions on the file are, it only matters what the permissions of
- the directory the file is contained in. So, for example, if your /etc
- directory is set to have write permission for everyone (which it
- shouldn't, for the reasons you pointed out), anybody can write to the
- directory such as by creating or deleting entries.
-
- If the 'sticky' flag is set for a directory, users can only delete
- files they own - this flag is typically set for /usr/tmp, /tmp,
- /usr/spool/mail, and other places.
-
- I suspect one of the many permissions fixes that Peter Macdonald has
- released for SLS sets the permissions of /etc to something more safe.
- --
- loveritablessencentipedependentalism+ Jim Winstead Jr. (CSci '95)
- andaterrificklengtherealityearguessy| Harvey Mudd College, WIBSTR
- mpathybridgenerationiceremonymphysic| jwinstea@jarthur.Claremont.EDU
- alendareadvertisexpresshothoughthend+ or jwinstea@fenris.Claremont.EDU
-