[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE-2017-8805: Unsafe symlinks not filtered in Debian mirror script ftpsync
From:       Robert Watson <robertcwatson1 () gmail ! com>
Date:       2017-10-21 19:57:52
Message-ID: CAOfWR+E5EBSOe5kbSFh2zwUXKAahDXi6Dpax6dr9FLVkT1pY3g () mail ! gmail ! com
[Download RAW message or body]

Thank You for tolerating my questions. I've read the wikis and pages
you've suggested, and am attempting to format this reply as required.
Please advise if anything is still wrong.


On Sat, Oct 21, 2017 at 6:58 AM, Solar Designer <solar@openwall.com> wrote:
>
>
> On Fri, Oct 20, 2017 at 11:08:14PM +0000, Robert Watson wrote:
> > Okay, so a script adds a symlink to /etc/shadow or something else
> > confidential. Unless they're root, what good does it do them? They can't
> > read it.
>
> I think this specific question had already been addressed by Ben in:
>
> http://www.openwall.com/lists/oss-security/2017/10/18/12
> ...

I didn't see how revealing configuration details was anything more
than "security by obscurity" but that's not a discussion for this
forum. Mea Culpa.

> While we're at it, I also recommend that you avoid top-posting and
> over-quoting.  Here's how to format your messages better:

Believe it or not, this is first occasion using the "Plain text"
feature in the browser version of Gmail and editing the included text.
Was using Google Inbox on a tablet before. I write programs. Really
pretty naive when it comes to skillfully using software.

Will use this in the future.

Robert
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic