Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 14 Dec 1996 16:28:36 -0500 (EST)
From:      John Dowdal <jdowdal@destiny.erols.com>
To:        proff@suburbia.net
Cc:        Steve Reid <steve@edmweb.com>, hackers@freebsd.org, security@freebsd.org
Subject:   Re: questions...
Message-ID:  <Pine.BSI.3.95.961214162415.20730A-100000@destiny.erols.com>
In-Reply-To: <19961214204416.972.qmail@suburbia.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, 15 Dec 1996 proff@suburbia.net wrote:

> Unfortunately this isn't a total cure, because there are 1001 stack overflows
> in NON-suid programs.

So what.  The programs will just core dump if they stack overflow, else
just not work right.  Since they are not SUID and not run as root [inetd,
...], they won't be able to get root if they blow up.

John




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSI.3.95.961214162415.20730A-100000>