Debian Developers - restricting /dev/vc/* to root.tty 660

This is Interesting: Free IT Magazines  
Home > Archive > Debian Developers > August 2004 > restricting /dev/vc/* to root.tty 660





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author restricting /dev/vc/* to root.tty 660
Arthur Korn

2004-08-29, 5:52 pm

Hi

devfs users currently have /dev/vc/* owned by root.tty but mode
666, which poses a security risk i'm said. In any event just
cating /dev/vc/0 has interesting effects, and is kind of a DoS
attack ...

Maybe the security team wants to publish an advisory, I have no
idea if this can be used for password sniffing or such.

People who need to access those should be added to the tty
group.

If this is a problem, let me know please.

ciao, 2ri
--
Help securing email, spread GPG, clearsign all mail. http://www.gnupg.org
.
Procter & Gamble, for example, uses an SGI system to study the
aerodynamics of Pringle's potato chips, Snell said. The chips move
along a conveyor belt so fast that they actually take flight.
-- SGI press release regarding the Origin 3900

Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com