Re: crontab from vixie-cron allows read other users crontabs

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 





Karol Więsek wrote:
but also checks entrys, so attacker is only able to read properly
formated crontab files (another users crontabs).

It should be noted that files other than crontabs are valid files as far as cron is concerned. This is because crontabs may contain variable assignments and comments. This means that it may be possible to read other configuration files or scripts that confirm to the syntax used by cron.

Cheers

Rich.
--
Richard Moore, Principle Software Engineer,
Westpoint Ltd,
Albion Wharf, 19 Albion Street, Manchester, M1 5LN, England
Tel: +44 161 237 1028
Fax: +44 161 237 1031

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux