Re: Call for review: restricted hardlinks.

From: Pawel Jakub Dawidek (pjd_at_FreeBSD.org)
Date: 03/09/04

  • Next message: Tim Robbins: "Re: Call for review: restricted hardlinks."
    Date: Tue, 9 Mar 2004 10:23:09 +0100
    To: CÚdric Devillers <cedric.devillers@script.jussieu.fr>
    
    
    

    On Tue, Mar 09, 2004 at 09:16:39AM +0100, CÚdric Devillers wrote:
    +> If you create several partition ( /var /usr /home ), this problem is
    +> resolved. Generally, in /usr, there are no directory write-able for all.
    +> If you have a partition for /usr, no hard link to a set-uid binary ( in
    +> the /usr tree ) is possible.

    Believe me, I'm aware of this.
    This "issue" can be used to other purposes as well.

            % ln /home/<user>/important_file ~/i_cannot_read_it_now_but_maybe_some_day_i_will_compromise_this_machine

    Anyway, it is turned off by default and there is no need to use it at all.

    -- 
    Pawel Jakub Dawidek                       http://www.FreeBSD.org
    pjd@FreeBSD.org                           http://garage.freebsd.pl
    FreeBSD committer                         Am I Evil? Yes, I Am!
    
    



  • Next message: Tim Robbins: "Re: Call for review: restricted hardlinks."

    Relevant Pages

    • Re: Active Directory
      ... Do "View | Tree" and select the domain naming context from the list. ... won't be either the configuration partition or the schema partition and will ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
      (microsoft.public.windows.server.security)
    • Re: Hard links to directories
      ... ln -d usr usr-link ... to a new partition on another disk. ... had planned to do was mount the new partition as /usr-new, ... You can't do a hard link across partitions.. ...
      (alt.os.linux.suse)
    • Re: [PATCH] cowlinks v2
      ... >> All of which works great until you have a file that has one hard link ... >> any cow. ... > both trees, or the link inside the original tree, it will only affect ... That converts the original directory inode ...
      (Linux-Kernel)
    • Re: Part 1 (of 3): What are major aspects of evolutionary theory?
      ... decomposition of unrooted tree into singly-attached-side-chains (what ... Fourty experts get together and look at the unrooted tree. ... taxon is a true clade. ... But "partition" is most definitely not correct ...
      (talk.origins)
    • [Full-Disclosure] Re: hard links on Linux create local DoS vulnerability and security problems
      ... >on Linux it is possible for any user to create a hard link to a file belonging ... Only if they can write to some directory on the same partition. ... I think that this is too drastic a change to the semantics of the unix ...
      (Full-Disclosure)