Date: Thu, 13 Aug 1998 15:22:39 -0700 (PDT) From: Ben <spy@tyr.office.efn.org> To: Nicole Harrington <nicole@mediacity.com> Cc: andrewr <andrewr@slack.net>, ben@efn.org, freebsd-security@FreeBSD.ORG Subject: Re: Possible security "risk" in ftp client Message-ID: <Pine.BSF.3.96.980813152153.24003B-100000@Tyr.office.EFN.org> In-Reply-To: <Chameleon.903030774.nicole@mobil1.mediacity.com>
next in thread | previous in thread | raw e-mail | index | archive | help
15:29.root@ben.v0(0)[/usr/src/usr.bin/fstat]759# ls -l /dev/mem 1129 0 crw-r----- 1 root kmem 2, 0 Mar 24 17:56:50 1998 /dev/mem It's also amazing when people forget when they are logged in as root. -ben@efn.org On Thu, 13 Aug 1998, Nicole Harrington wrote: > > > Maybe I'm mistaken, but ps(1) get's the info from /dev/kmem and /dev/mem and > > formats them according to /kernel, what would I need to patch? > > > > It's rather amazing the amount of info you can get by doing strings /dev/mem > > Nicole > > > > On Wed, 12 Aug 1998, andrewr wrote: > > > > > > > > > > > On Wed, 12 Aug 1998, Ben wrote: > > > > > > > For ps I made a patch that allows only root(or wheel, you pick) to use the > > > > flag '-a', otherwise the user attempting to use '-a' only gets his/her proc's. > > > > > > Did you patch the kernel as well? Caue if you didn't, it's useless. > > > > -ben@efn.org > > > > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > > with "unsubscribe security" in the body of the message > > > > ---------------End of Original Message----------------- > > > |\ __ /| (`\ > | o_o |__ ) ) > // \\ > Nicole Harrington | SR Systems Administrator > -------------------(((---(((----------------------- > > nicole@mediacity.com - nicole@ispchannel.com > www.mediacity.com - www.ispchannel.com > Phone: 650-237-1464 - Pager: 415-301-2482 > > Powered By Coca-Cola and FreeBSD > > Why do doctors call what they do practice? > Microsoft: What bug would you like today? > ---------------------------------------------------- > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe security" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.96.980813152153.24003B-100000>
