Date: Sat, 18 May 1996 00:17:24 -0400 (EDT) From: James FitzGibbon <james@nexis.net> To: Glen Foster <gfoster@gfoster.com> Cc: security@FreeBSD.org Subject: Re: cvs commit: src/sbin Makefile Message-ID: <Pine.BSI.3.93.960518001608.2342B-100000@bdd.net> In-Reply-To: <199605171948.PAA00619@ptavv.nsta.org>
next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 17 May 1996, Glen Foster wrote: > How about rather than changing the Makefile to not install suid, the > full path of modload be referenced in the source. Preserves the suid > functionality and defeats the symlink attack. Alternatively, the union fs could be set as only available statically, couldn't it? If it didn't try to load an lkm, modload would never be referenced, by relative or absolute path. -- j. ---------------------------------------------------------------------------- | James FitzGibbon james@nexis.net | | Integrator, The Nexis Group Voice/Fax : 416 410-0100 | ----------------------------------------------------------------------------
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSI.3.93.960518001608.2342B-100000>