From owner-freebsd-bugs@FreeBSD.ORG Thu Apr 13 14:00:33 2006 Return-Path: X-Original-To: freebsd-bugs@hub.freebsd.org Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 40F8A16A404 for ; Thu, 13 Apr 2006 14:00:33 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id E3D5F43D49 for ; Thu, 13 Apr 2006 14:00:32 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.4/8.13.4) with ESMTP id k3DE0WTV053163 for ; Thu, 13 Apr 2006 14:00:32 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.4/8.13.4/Submit) id k3DE0WSe053160; Thu, 13 Apr 2006 14:00:32 GMT (envelope-from gnats) Date: Thu, 13 Apr 2006 14:00:32 GMT Message-Id: <200604131400.k3DE0WSe053160@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: Jerry McAllister Cc: Subject: Re: misc/95684: /root wrong permissions X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Jerry McAllister List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 13 Apr 2006 14:00:33 -0000 The following reply was made to PR misc/95684; it has been noted by GNATS. From: Jerry McAllister To: c_dornig@gmx.de (C.D.) Cc: freebsd-gnats-submit@freebsd.org Subject: Re: misc/95684: /root wrong permissions Date: Thu, 13 Apr 2006 09:59:31 -0400 (EDT) > > > >Number: 95684 > >Category: misc > >Synopsis: /root wrong permissions > >Confidential: no > >Severity: critical > >Priority: medium > >Responsible: freebsd-bugs > >State: open > >Quarter: > >Keywords: > >Date-Required: > >Class: sw-bug > >Submitter-Id: current-users > >Arrival-Date: Thu Apr 13 09:50:15 GMT 2006 > >Closed-Date: > >Last-Modified: > >Originator: C.D. > >Release: 5.4 RELEASE, 6.0 RELEASE > >Organization: > none > >Environment: > >Description: > Dear FreeBSD Team, > > > > with standard installation of FBSD 5.4 Released or 6.0 Released from CD-ROM, > you have after install process a wrong permission of /root. > It is 0755, but it should be 0700. > I see this as an Security hole. I was just able to look back as far as FreeBSD 3.2 - as far back as I have anything handy running and they all have "/" set to 755. I don't understand why it should be 0700. If you did that, no person could do an ls or get to directories under root. The 755 setting does not allow group or world to write to root, just get to the necessary things in it. ////jerry > >How-To-Repeat: > Install FBSD and make: > > ls -l > > >Fix: > Change install script. > >Release-Note: > >Audit-Trail: > >Unformatted: > _______________________________________________ > freebsd-bugs@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-bugs > To unsubscribe, send any mail to "freebsd-bugs-unsubscribe@freebsd.org" >