Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 9 Sep 2001 01:36:55 -0700 (PDT)
From:      Matt Dillon <dillon@earth.backplane.com>
To:        Bruce Evans <bde@zeta.org.au>
Cc:        Mike Tancsa <mike@sentex.net>, <security@FreeBSD.ORG>
Subject:   Re: Fwd: Multiple vendor 'Taylor UUCP' problems.
Message-ID:  <200109090836.f898atk32035@earth.backplane.com>
References:   <20010909174638.Q3607-100000@alphplex.bde.org>

next in thread | previous in thread | raw e-mail | index | archive | help
:I don't see how schg'ing these binaries makes them significantly more
:secure.  These binaries are not writable by uucp.  They are writable
:by root, but root can just as easily un-schg them as write them.
:

    Huh?  The binaries are owned by user uucp, so they are writable by
    user uucp.

    su - uucp
    cd /usr/bin
    chmod 755 uucp
    vi uucp
    (have fun)
    chmod 4555 uucp

						-Matt

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200109090836.f898atk32035>