Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 19 May 1997 19:35:35 +0400 (DST)
From:      "Sergei S. Laskavy" <laskavy@cs.msu.su>
To:        hackers@FreeBSD.ORG
Subject:   drwxr-xr-x  2 bin  bin  /usr/sbin
Message-ID:  <199705191535.TAA23174@ns.cs.msu.su>

next in thread | raw e-mail | index | archive | help
eric@Sendmail.ORG said, that

+----------------------------------------------+
| For security reasons, /, /usr, and /usr/sbin |
|      should be owned by root, mode 755.      |
+----------------------------------------------+

I think that someone can gain "bin" and then replace
	/usr/sbin/GOOD_PROGGY
by
	/usr/sbin/EVIL_PROGGY



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199705191535.TAA23174>