Re: again security proposal

Egor Egorov (egor@fastware.kiev.ua)
Tue, 30 Dec 1997 21:38:16 +0000 (GMT)


On Mon, 29 Dec 1997, Alan Cox wrote:

> > user. Well known hardlink attack ($ ln /etc/passwd ~/.somestuff; # chown user
> > /home/user -R; $ vi ~/.somestuff) now maybe done by any user. Any sysadmin
> If it can be then its a bug in 2.1.x

> So I think you are seeing things

Alan, you forgot: yuri told, that _root's_ crontab can do periodically
chown -R.

// Егор Егоров.
// http://frigate.kiev.ua/~egor/