Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 19 Apr 1998 20:39:48 +0000
From:      Niall Smart <rotel@indigo.ie>
To:        Marc Slemko <marcs@znep.com>, Karl Denninger <karl@mcs.net>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: suid/sgid programs
Message-ID:  <199804191939.UAA01293@indigo.ie>
In-Reply-To: Marc Slemko <marcs@znep.com> "Re: suid/sgid programs" (Apr 19, 12:25pm)

next in thread | previous in thread | raw e-mail | index | archive | help
On Apr 19, 12:25pm, Marc Slemko wrote:
} Subject: Re: suid/sgid programs
> On Sun, 19 Apr 1998, Karl Denninger wrote:
> 
> > Things like "ccdconfig" simply don't need to be run as a user process.
> > If someone is going to be setting up a ccd set, they are ALREADY going to 
> > be root!
> 
> Erm... but if someone wants to see what ccds are configured, they don't
> need to be root and shouldn't.

So you want an extra sgid kmem utility just because you like your curious
users to be able to see what your ccd configuration is?  How useful is
that?  Not very.  Do it locally if you really must.

Niall

-- 
Niall Smart.        PGP: finger njs3@motmot.doc.ic.ac.uk
FreeBSD: Turning PC's into Workstations: www.freebsd.org
Annoy your enemies and astonish your friends:
echo "#define if(x) if (!(x))" >> /usr/include/stdio.h

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199804191939.UAA01293>