From owner-freebsd-questions Tue Apr 4 12:52:03 1995 Return-Path: questions-owner Received: (from majordom@localhost) by freefall.cdrom.com (8.6.10/8.6.6) id MAA21400 for questions-outgoing; Tue, 4 Apr 1995 12:52:03 -0700 Received: from csvax1.ucc.ie (csvax1.ucc.ie [143.239.1.10]) by freefall.cdrom.com (8.6.10/8.6.6) with SMTP id MAA21390 for ; Tue, 4 Apr 1995 12:51:56 -0700 Received: from csws2.ucc.ie by csvax1.ucc.ie (MX V4.1 VAX) with SMTP; Tue, 04 Apr 1995 20:51:07 BST Received: by csws2.ucc.ie (5.57/Ultrix3.0-C) id AA05978; Tue, 4 Apr 95 20:52:21 +0100 Date: Tue, 4 Apr 95 20:52:21 +0100 From: dave@odyssey.ucc.ie (David B. O'Byrne) Message-ID: <9504041952.AA05978@csws2.ucc.ie> To: freebsd-questions@FreeBSD.org Subject: RE: atrun hole Sender: questions-owner@FreeBSD.org Precedence: bulk Hi, I want to post a query about the atrun security hole described by Adam (adam@math.tau.ac.il). Is it enough to just chmod 0700 /var/at/jobs or is this too simplistic ? I have about 50 FreeBSD boxes, so a quick stop gap before installing the patched atrun (ftp://sunsite.unc.edu/pub/Linux/system/Daemons/at-2.7a.tgz for those who do not feel a subscription to the freebsd-security list is right). I post the question here as I think questions is a more appropriate forum, and I do not want to clutter the security list... thank you David