Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 9 Dec 2011 00:25:10 -0800
From:      Xin LI <delphij@gmail.com>
To:        gabor@zahemszky.hu
Cc:        freebsd-security@freebsd.org
Subject:   Re: ftpd security issue ?
Message-ID:  <CAGMYy3vZ9CjuboiQsuGnYLZPpbAMMCQScsu9toXLpOyWAdAA3A@mail.gmail.com>
In-Reply-To: <c081e4612df771d59c1dc2870d99d7b9@zahemszky.hu>
References:  <4ED68B4D.4020004@sentex.net> <4ED69B7E.50505@frasunek.com> <4ED6C3C6.5030402@delphij.net> <4ED6D1CD.9080700@sentex.net> <4ED6D577.9010007@delphij.net> <4ED6DA75.30604@sentex.net> <4EE131B8.7040000@sentex.net> <c081e4612df771d59c1dc2870d99d7b9@zahemszky.hu>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, Dec 9, 2011 at 12:04 AM,  <gabor@zahemszky.hu> wrote:
> Hi!
>
> Are the following steps enough to prevent me?
>
> # for user in user1 user2 .... ; do
> mkdir -p ~$user/lib ~$user/usr/lib ~$user/etc
> chflags sunlink,schg ~$user/lib ~$user/usr ~$user/usr/lib ~$user/etc
> done
> #

Yes that should be sufficient workaround.

Cheers,
-- 
Xin LI <delphij@delphij.net> https://www.delphij.net/
FreeBSD - The Power to Serve! Live free or die



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAGMYy3vZ9CjuboiQsuGnYLZPpbAMMCQScsu9toXLpOyWAdAA3A>