Re: [Full-Disclosure] Syscall implementation could lead to whether or not a file exists

From: Arjan van de Ven (arjanv@redhat.com)
Date: 04/07/03

  • Next message: Georgi Guninski: "[Full-Disclosure] U.S. military helps fund Calgary hacker with $2.3 million"
    From: Arjan van de Ven <arjanv@redhat.com>
    To: Andrew Griffiths <andrewg@d2.net.au>
    Date: 07 Apr 2003 12:47:00 +0200
    

    On Wed, 2003-04-02 at 21:19, Andrew Griffiths wrote:
    > Product: Linux and various other kernels
    > Tested:
    > - RedHat kernel 2.4.18-26.7.x (second latest ;))
    > - RedHat kernel 2.4.18-27.7.x
    > - Debian 3.0 box
    > - FreeBSD 4.4
    >
    > Description:
    >
    > Due to the implementation of various system calls, it becomes
    > possible to test whether or not a file exists in a directory
    > that is unreadable.

    .. by calling lstat(2). Ability to do lookup is controlled by _exec_
    permissions, not read ones.

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Georgi Guninski: "[Full-Disclosure] U.S. military helps fund Calgary hacker with $2.3 million"

    Relevant Pages

    • oprofile can cause an NMI to schedule (was: [RT] scheduling and oprofile)
      ... It seems strange to me that oprofile would be calling ... when we generate a page fault in this context on non-RT kernels? ... As Mike has pointed out here, oprofile _can_ cause the nmi to schedule. ...
      (Linux-Kernel)
    • Re: Materazzi red carded awesome!
      ... ability why you repeat the questions I put to you? ... Where have I lacked integriy and intellectual ability, ... mind numbing mind-reads on me and my biographical details - an art ... I'm just calling you out, ...
      (rec.sport.soccer)
    • Re: Looking for best defrag program
      ... But they are often marginal on their features and ability. ... party defrag tools use the Windows function, ... Calling an illegal alien an "undocumented worker" is like calling a ...
      (microsoft.public.windowsxp.general)
    • Re: A Ruling
      ... >Another question for anybody who knows - when does the 2S bidder and ... >teammates lose their ability to call the TD about this - after the ... the time for calling the TD in the first place. ...
      (rec.games.bridge)
    • Re: ITBasicCall.Connect - synchronous or asynchronous
      ... my first post should read ITBasicCallControl.Connect. ... I am about to release some code to a customer that just gives them the ... ability to dial a call from our application. ... At the moment I am calling Connect, synchronously, but this means ...
      (microsoft.public.win32.programmer.tapi)

    Loading