Subject: Re: Making setuid files immutable
To: Manuel Bouyer <bouyer@antioche.lip6.fr>
From: Todd Vierling <tv@pobox.com>
List: tech-security
Date: 01/15/1999 12:24:03
On Fri, 15 Jan 1999, Manuel Bouyer wrote:

: > You'd probably want more than just setuid files as immutable.  On my
: > system, the following are immutable :
: > [list of file]
: 
: Remember to mark immutable the directories too, or the hacxker can
: still mv the file and install a new one.

Not on my NetBSD, you can't.  rename(2) doesn't work on an immutable file,
and I've never seen it work on 4.4BSD derived systems.  :>

-- 
-- Todd Vierling (Personal tv@pobox.com; Bus. todd_vierling@xn.xerox.com)