Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 10 Feb 2002 02:20:02 -0800 (PST)
From:      Mike Makonnen <mike_makonnen@yahoo.com>
To:        freebsd-bugs@FreeBSD.org
Subject:   Re: conf/34780: locate(1)'s database is generated with root	permissions
Message-ID:  <200202101020.g1AAK2l64767@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help
The following reply was made to PR conf/34780; it has been noted by GNATS.

From: Mike Makonnen <mike_makonnen@yahoo.com>
To: "f. johan beisser" <jan@caustic.org>
Cc: freebsd-gnats-submit@freebsd.org
Subject: Re: conf/34780: locate(1)'s database is generated with root	permissions
Date: Sun, 10 Feb 2002 02:17:25 -0800

 On Sat, 2002-02-09 at 18:29, f. johan beisser wrote:
 >       the locate(1) database is generated with root permissions. this allows any user to find the existance of any other users files through the locate(1) command. 
 > this means doing a search for any users login, you can get a list of 
 > all of the files in their home direcotry, no matter what permissions 
 > the file has.
 
 Yes, it is called by root, but the script su's to user nobody before
 updating the database.
 
 
 cheers,
 mike makonnen

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-bugs" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200202101020.g1AAK2l64767>