Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 19 Jul 1997 23:36:49 +1000 (EST)
From:      "Daniel O'Callaghan" <danny@panda.hilink.com.au>
To:        Wolfgang Helbig <helbig@MX.BA-Stuttgart.De>
Cc:        sthaug@nethelp.no, andreas@klemm.gtn.com, hackers@FreeBSD.ORG
Subject:   Re: sendmail complains about being unable to write his pid file
Message-ID:  <Pine.BSF.3.91.970719233540.869J-100000@panda.hilink.com.au>
In-Reply-To: <199707191241.OAA28753@helbig.informatik.ba-stuttgart.de>

next in thread | previous in thread | raw e-mail | index | archive | help

On Sat, 19 Jul 1997, Wolfgang Helbig wrote:

> > Yes, but the question stands - why is it setup this way? What is gained
> > by having binaries (and important directories) owned by bin instead of
> > root?
> 
> More security? setuid / setgid will give you the powers of bin
> only, not of root.

If you gain access to bin, you can write a tojan 'ls', or other command 
likely to be run by root.

Danny



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.91.970719233540.869J-100000>