New User, Welcome!     Login

Re: /proc filesystem allows bypassing directory permissions on Linux

From: Pavel Kankovsky <peak argo troja mff cuni cz>
To: Pavel Machek <pavel ucw cz>
Cc: bugtraq securityfocus com
Subject: Re: /proc filesystem allows bypassing directory permissions on Linux
Date: Mon - Oct 26, 2009 04:03 AM


On Sun, 25 Oct 2009, Pavel Kankovsky wrote:

> pavel might have detected this attack if he checked the number of
> hardlinks on "unwritable_file"  between the chmod's. But he did not
> check that.

I stand corrected. He did it--in a comment:

> # check link count on unwritable_file. We would not want someone 
> # to have a hard link to work around our permissions, would we?

-- 
Pavel Kankovsky aka Peak                          / Jeremiah 9:21        \
"For death is come up into our MS Windows(tm)..." \ 21st century edition /






Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!