Re: Call for review: restricted hardlinks.

From: Pawel Jakub Dawidek (pjd_at_FreeBSD.org)
Date: 03/08/04

  • Next message: Cédric Devillers: "Re: Call for review: restricted hardlinks."
    Date: Mon, 8 Mar 2004 23:08:28 +0100
    To: "Georg-W. Koltermann" <gwk@rahn-koltermann.de>
    
    
    

    On Mon, Mar 08, 2004 at 10:10:38PM +0100, Georg-W. Koltermann wrote:
    +> When you restrict links, do you want to restrict copying as well?
    +>
    +> Seems somewhat paranoid to me. You already need write permission on the
    +> directory where you create the link, and permissions are checked against
    +> the inode on open(2) anyway.

    This is because this gives an attacker some possibilities.
    For example he is able to create hard link to some set-uid binary.
    After some time, a security-related bug will be found in this application,
    administrator will change it with good version, but old, vulnerable
    version will be still in system.
    Administrator have to be really careful when fixing such problems
    and check number of hard links or just remove such program using 'rm -P'.

    -- 
    Pawel Jakub Dawidek                       http://www.FreeBSD.org
    pjd@FreeBSD.org                           http://garage.freebsd.pl
    FreeBSD committer                         Am I Evil? Yes, I Am!
    
    



  • Next message: Cédric Devillers: "Re: Call for review: restricted hardlinks."

    Relevant Pages

    • Re: 837272 & 839643 Updates wont install on W2K SP4 domain PCs - Permission Error
      ... > 3.455: Failed To Enable SE_BACKUP_PRIVILEGE> 3.565: Setup encountered an error: You do not have> permission to update Windows 2000. ... > Please contact your system administrator. ...
      (microsoft.public.windowsupdate)
    • Re: XP Accessibility feature saving profile
      ... >> think you should have the System Administrator, ... >>> the network storage they provide or my thumbdrive and restore it for my ... I have WRITTEN permission + if they refused to ... >>>> multi-user environments to protect setups from exactly the kind of ...
      (microsoft.public.windowsxp.accessibility)
    • Re: Administrator account has "SEND AS" right on every Mailbox
      ... We all know Administrator can change any permission in AD. ... > dutch SBS 2003 servers. ... >> probably by Exchange Installation. ...
      (microsoft.public.exchange.admin)
    • Re: Office 2007 Docs open read only from Webdav folder
      ... "I did copy all the files while logged on as administrator. ... I had copied them all into the Shared Documents" ... Users should have PERMISSION to access the Shared Docs directory. ... assume that your user account can access these files on your backup ...
      (microsoft.public.office.misc)
    • Re: folder with no permission?!
      ... change the permission as administrator but can do it as the work account ... when granting the work account with administrative privilege. ... You have indicated "I cannot change anything inside this folder and I ...
      (microsoft.public.windowsxp.security_admin)