Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 24 Sep 2004 15:50:41 -0000
From:      Kris Kennaway <kris@obsecurity.org>
To:        dwbear75@gmail.com
Cc:        security@FreeBSD.ORG
Subject:   Re: Locate revealing contents of root:wheel 700 directories
Message-ID:  <20020421153805.A22029@xor.obsecurity.org>
In-Reply-To: <"from danm"@prime.gushi.org>
References:  <20020421131741.U39364-100000@prime.gushi.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--liOOAslEiF7prFVr
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

On Sun, Apr 21, 2002 at 01:27:14PM -0400, Dan Mahoney, System Admin wrote:
> Hi, I noticed that in freeBSD 4.5, locate shows the contents of all
> folders, even in my previously root:wheel 700 directory, /mnt/var/log.

Only if you run the locate.updatedb utility as root (i.e. in a
non-default way).  locate only searches the database, it doesn't have
any extra privileges.

Kris

--liOOAslEiF7prFVr
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE8wz9MWry0BWjoQKURAg3EAJ9rY5SqD4J7cR8lZKtZ0n6NiGyNjACdFyAn
LNZibPaHQkRBI810MWX4PDE=
=s0ML
-----END PGP SIGNATURE-----

--liOOAslEiF7prFVr--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020421153805.A22029>