tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Hard link creation witout write access



On Thu, Sep 7 2023, Mouse wrote:

What issues?  The only one I can see is that it allows anyone who can
write to any directory on that filesystem to cause the file to stick
around after its original name is unlinked.


Then you can make private copies of setuid binaries which you can exploit
at your leisure--even after the sysadmin's installed a new version. :)

-RVP


Home | Main Index | Thread Index | Old Index