Skip to Content [alt-c]
In reply to Security Pitfalls of setgid Programs
Except that with (just) setuid the attacker could use "umask 002" and then since the group didn't change, he'll still be able to modify the tmpfile...
The correct way to handle things for any non-god entity is to not use setuid or setgid at all, but rely on sudo instead. That is the proper scrutinizer program that you should use.
Reply
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.
Your Name: (Optional; will be published)
Your Email Address: (Optional; will not be published)
Your Website: (Optional; will be published)
>
monospaced
Post a Reply
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.