Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 18 May 1996 00:17:24 -0400 (EDT)
From:      James FitzGibbon <james@nexis.net>
To:        Glen Foster <gfoster@gfoster.com>
Cc:        security@FreeBSD.org
Subject:   Re: cvs commit: src/sbin Makefile
Message-ID:  <Pine.BSI.3.93.960518001608.2342B-100000@bdd.net>
In-Reply-To: <199605171948.PAA00619@ptavv.nsta.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 17 May 1996, Glen Foster wrote:

> How about rather than changing the Makefile to not install suid, the
> full path of modload be referenced in the source.  Preserves the suid
> functionality and defeats the symlink attack.

Alternatively, the union fs could be set as only available statically,
couldn't it?  If it didn't try to load an lkm, modload would never be
referenced, by relative or absolute path.



--
j.

----------------------------------------------------------------------------
| James FitzGibbon                                         james@nexis.net |
| Integrator, The Nexis Group                     Voice/Fax : 416 410-0100 |
----------------------------------------------------------------------------




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSI.3.93.960518001608.2342B-100000>