Re: Your backup is unsafe!

Alexander Viro (viro@math.psu.edu)
Sun, 1 Aug 1999 01:29:53 -0400 (EDT)


On Sun, 1 Aug 1999, Khimenko Victor wrote:

> You can run dosemu or you can write something like doslfnbk for Linux :-)
> At your choice. No kernel modifications are needed...

Especially since required ioctls are there. Idea about hardlinks is
braindead - sorry, but we *can't* allow multiple dentries for a directory
with our VFS. Anyone who does it has (and acknowledges) severe races
around the thing and carefully restricts it to root. And yes, I consider
write access to AFFS as security breach (it allows hardlinks to
directories) - I can crash the box in a couple of minutes once I've got
such access. With a little more work - make it execute my code in ring 0.
Again, *normal* *user* *can* *cause* *stack* *smashing* *in* *kernel*
*mode* once he has an ability to hardlink directories. Sorry, but such
things should not be allowed. At all.

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/