Subject: ktrace
To: None <tech-security@netbsd.org>
From: Emmanuel Dreyfus <p99dreyf@criens.u-psud.fr>
List: tech-security
Date: 01/15/2001 16:56:30
When running ktrace as root, the ktrace.out file is created according to
root's umask. Don't you think it would be better to force that file to
mode 600? 

As it is today, a negligent system administrator can leave a
world-readable ktrace.out file in the filesystem, and this file might
contain sensitive information 

Opinions?

-- 
Emmanuel Dreyfus.  
Hiroshima 45. Tchernobyl 86. Windows 95. 
p99dreyf@criens.u-psud.fr