|
Save the teapot fund New CSS web design for Wibble proudly provided by Kelv. Please contact the webmaster with any questions or concerns. |
Wibble > List archives > bugtraq > 1998 [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: Verity/Search'97 Security Problems
+--Jay Soffian <jay@xxxxxxxxxxxxxxxxxxxx> once said: | | |Obviously, you want to either make verity_path_post something less |obvious than ".orig" or you want to suid the wrapper to some |unprivledged user and make the ".orig" file executable by only that |user. | |Duh. Last message, I promise. My brain isn't working today. suid (or sgid) is a terrible idea. Using something other than '.orig' works, but that's security by obscurity. Probably, you are best using a <files> section (or equiv if not Apache) to protect the '.orig' binaries. j. -- Jay Soffian <jay@xxxxxxxxxxx> UNIX Systems Administrator 404.572.1941 Cox Interactive Media
|