Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 26 Jan 1996 09:49:41 +0000 (GMT)
From:      Paul Richards <p.richards@elsevier.co.uk>
To:        obrien@cs.ucdavis.edu (David E. O'Brien)
Cc:        security@FreeBSD.org
Subject:   Re: Ownership of files/tcp_wrappers port
Message-ID:  <199601260949.JAA11440@cadair.elsevier.co.uk>
In-Reply-To: <9601260937.AA00228@toadflax.cs.ucdavis.edu> from "David E. O'Brien" at Jan 26, 96 01:37:32 am

next in thread | previous in thread | raw e-mail | index | archive | help
In reply to David E. O'Brien who said
> 
> As demonistrated by Nathan Lawson <nlawson@statler.csc.calpoly.edu>,
> having system binaries owned by ``bin'' has serious security flaws that
> would be reduced by having them owned by ``root'', the *real* question is
> how do we go about _offically_ changing this?
> 

guys, these are NFS problems. If you want to stop people su'ing to bin
then map bin to nobody as well.

-- 
  Paul Richards. Originative Solutions Ltd.
  Internet: paul@netcraft.co.uk, http://www.netcraft.co.uk
  Phone: 0370 462071 (Mobile), +44 1225 447500 (work)



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199601260949.JAA11440>