TIP: Click on subject to list as thread! ANSI
echo: unix
to: Angus Mcleod
from: Jasen Betts
date: 2004-08-23 09:44:58
subject: This is why FreeBSD...

Hello Angus.

14 Aug 04 05:32, you wrote to Takumi:

 AM> {at}TZUTC: -0400
 AM> {at}MSGID: 1:275/312 05833257 1150.doveunix 05833257
 AM> {at}TID: SBBSecho 2.10-Win32 r1.131 Apr  3 2004 MSC 1200
 AM>   Re: This is why FreeBSD...
 AM>   By: Takumi to Angus Mcleod on Sat Aug 14 2004 02:07:00

 >> If you want someone else to own a file, write it yourself, and get
 >> them to c it.

 AM> Doesn't wash.  The entire chown command is useless if you can't
 AM> actually USE it.

you can use it instead of chgrp, (to change the group of a file) so it's
not totally useless.

 AM>   Of you're worried about setuid/setgid then make
 AM> chown non-functional for files with setuid/setgid bits set.

But then you still can fill /tmp with junk and blame someone else!

 AM>   Or to be
 AM> really strict, make it so you can only chown to your own userid (with
 AM> read perms on the other guys file(s), of course).

that'd mean you can steal someone elses file and then deny them access to it.

Jasen

--- GoldED+/LNX 1.1.4.7
* Origin: (3:640/1042)
SEEN-BY: 633/267 270
@PATH: 640/1042 531 954 774/605 123/500 106/2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.