Re: protecting /sbin and /usr/local/sbin

From: Matt Piechota (piechota@argolis.org)
Date: 09/13/01


Date: Thu, 13 Sep 2001 11:37:51 -0400 (EDT)
From: Matt Piechota <piechota@argolis.org>
To: Kris Kennaway <kris@obsecurity.org>

On Wed, 12 Sep 2001, Kris Kennaway wrote:

> You can do it, but if your system relies on non-root users executing
> these commands, bits will obviously fail. I think you're probably
> overreacting, though.

Plus, you're going to have to clamp down on compiling and such. Some one
could go find the source for whatever command and compile up their own
copy. Of course they could compile their own binary somewhere else and
transfer it over as well. You could make it harder for them, but you're
not going to be able to stop them from running the commands in question.

-- 
Matt Piechota
Finger piechota@emailempire.com for PGP key
AOL IM: cithaeron
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: what about now? [ADD == --]
    ... You posted TWO programs which show COMMANDS REVERSED in one of them. ... Logic would suggest that both versions should not compile the same, ... calculator, then regardless of how the flag is set, the editor would ... and can even be used within algebraic objects, as also can -NEGin algebraics ...
    (comp.sys.hp48)
  • Re: metapost or something? Coordinate system - transformation with cosine...
    ... following the `#include' commands, ... ctangle main.web ... Now ctangle `main.web', compile `main.c', and relink: ...
    (comp.text.tex)
  • Re: Access Extable from C?
    ... I think you really need to decompile and compile using the ... available CAS commands + other control commands like IF, ... Right now I'm looking to build a binary tree from a composite object ...
    (comp.sys.hp48)
  • Re: embedding password in program
    ... restricted to "authorized users". ... whenever they want to access restricted commands. ... compile time, at the preprocessor level, while the ... There's several, especially if security isn't a big issue, try rot13, ...
    (comp.lang.c)
  • embedding password in program
    ... I have a C program, used as a public cgi, where a few ... restricted to "authorized users". ... whenever they want to access restricted commands. ... compile time, at the preprocessor level, while the ...
    (comp.lang.c)