Re: Proposing Fedora Feature for private /tmp and /var/tmp for all systemd services in Fedora 17.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Lennart Poettering <mzerqung@xxxxxxxxxxx> writes:

> Well, that way attackers might still be able fool the admin: i.e. he
> could create a directory with a service name and some randomized suffix
> and the admin might blindly believe that this directory belongs to the
> service, even if it doesn't, but belongs to the evil attacker. Using a
> fully randomized name is a bit more secure here, since the admin always
> needs to check the service first for the actual directory.

How about making a non-world-writable directory somewhere for this
purpose, with service-named directories beneath it?

That is yet another thing for sysadms to learn about of course, unless
it is placed in /tmp itself which creates some security problems
again...


/Benny

-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel



[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux