Re: [UFS] Broken suiddir? (+patch)

From: Rafal Skoczylas <nils_at_secprog.org>
Date: Wed, 24 Mar 2004 22:52:27 +0100
On Wed, Mar 24, 2004 at 01:21:49PM -0500, Andre Guibert de Bruet wrote:
> On Tue, 23 Mar 2004, Rafal Skoczylas wrote:
> > Additionaly, would someone be so kind to describe the risk caused by using
> > SUIDDIR (mentioned in man) in more detail? Is there any "hidden" risk
> > except those obvious (like created files that look like if someone else
> > created them)? I tried searching google for such information but with
> > no luck so far.
> Imagine a scenario where a user uploads via SMB a windows executable and
> another trojans it. User 1 has no idea that the file has been tampered
> with and runs it. You've got yourself a problem.

Well, actually this is what I meant saying "obvious risk", i.e. you have
no clue who created the file and so on and so forth.

What I would like to know is whether there exists any known issue eg. race
condition in the kernel (or something like that) i.e. something that poses
risk to the system but cannot be thought of because of the nature of the
problem (eg. there's some known "buggie" behavior that makes it risky to
use). To be honest, I'd love to hear the only known risks are those which
I call "obvious" ;)

-- 
Rafal Skoczylas
Received on Wed Mar 24 2004 - 12:50:30 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:37:48 UTC