tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: hardlinks to setuid binaries



On Sun, Mar 27, 2022 at 01:47:44PM -0400, Thor Lancelot Simon wrote:
 > Even better, imagine requiring an attribute to be set on a directory
 > in order to _allow_ it to contain setuid executables.  Or device nodes.
 > Wouldn't that, in general, be safer and better than trying to decide all
 > the places where such things should _not_ be allowed?

That is a good idea...

-- 
David A. Holland
dholland%netbsd.org@localhost


Home | Main Index | Thread Index | Old Index