From owner-freebsd-security@FreeBSD.ORG Fri Dec 9 08:25:11 2011 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 536A0106564A for ; Fri, 9 Dec 2011 08:25:11 +0000 (UTC) (envelope-from delphij@gmail.com) Received: from mail-gx0-f182.google.com (mail-gx0-f182.google.com [209.85.161.182]) by mx1.freebsd.org (Postfix) with ESMTP id 141438FC1E for ; Fri, 9 Dec 2011 08:25:10 +0000 (UTC) Received: by ggnp1 with SMTP id p1so4146777ggn.13 for ; Fri, 09 Dec 2011 00:25:10 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=pYOgvF6y9tfVkk0vtFjzs+RjbuQdUoTnn7QiObX9BUw=; b=GejIT9R7VHdE2pPBqvPrvZI3v/IEzeVTPkLiCwj1C99mRDWzSABtVrHHt095Kqug91 ZQ0S7lHES/iZ/EeZu+gzkINdNgevwdysOIDRm4XJytwg5vLYTWZcdtpvTs6H3hKsm1bI Wb0suGVZy/uRofwRPhMVR5lxYMSanLE/lseLs= MIME-Version: 1.0 Received: by 10.182.41.69 with SMTP id d5mr251042obl.47.1323419110324; Fri, 09 Dec 2011 00:25:10 -0800 (PST) Received: by 10.182.15.196 with HTTP; Fri, 9 Dec 2011 00:25:10 -0800 (PST) In-Reply-To: References: <4ED68B4D.4020004@sentex.net> <4ED69B7E.50505@frasunek.com> <4ED6C3C6.5030402@delphij.net> <4ED6D1CD.9080700@sentex.net> <4ED6D577.9010007@delphij.net> <4ED6DA75.30604@sentex.net> <4EE131B8.7040000@sentex.net> Date: Fri, 9 Dec 2011 00:25:10 -0800 Message-ID: From: Xin LI To: gabor@zahemszky.hu Content-Type: text/plain; charset=UTF-8 Cc: freebsd-security@freebsd.org Subject: Re: ftpd security issue ? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 09 Dec 2011 08:25:11 -0000 X-List-Received-Date: Fri, 09 Dec 2011 08:25:11 -0000 X-List-Received-Date: Fri, 09 Dec 2011 08:25:11 -0000 X-List-Received-Date: Fri, 09 Dec 2011 08:25:11 -0000 X-List-Received-Date: Fri, 09 Dec 2011 08:25:11 -0000 X-List-Received-Date: Fri, 09 Dec 2011 08:25:11 -0000 X-List-Received-Date: Fri, 09 Dec 2011 08:25:11 -0000 On Fri, Dec 9, 2011 at 12:04 AM, wrote: > Hi! > > Are the following steps enough to prevent me? > > # for user in user1 user2 .... ; do > mkdir -p ~$user/lib ~$user/usr/lib ~$user/etc > chflags sunlink,schg ~$user/lib ~$user/usr ~$user/usr/lib ~$user/etc > done > # Yes that should be sufficient workaround. Cheers, -- Xin LI https://www.delphij.net/ FreeBSD - The Power to Serve! Live free or die