Re: /proc filesystem allows bypassing directory permissions on L

看板Bugtraq作者時間16年前 (2009/10/27 08:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串27/44 (看更多)
On 26.10.2009 18:14, nomail@nomail.com wrote: >>> I do not think mounting /proc should change access control semantics. >>> >> It didn't in fact change anything. If the guest created hardlink to that file in >> a unrestricted location, what would you say? > > Do your homework and test it. You can't create the hardlink - the link(oldpath, > newpath) call will fail with EACCES if search permission is denied for any > directory in oldpath or newpath. Documented in the manpage, and I just tested > and verified it. > Good boy. However, there wasn't worth both citing well known facts to me and testing them. Remember the scenario from the original mail and try finding a window, during which creating a hardlink would still work thus evading directory permissions check. -- Sincerely Your, Dan.
文章代碼(AID): #1AvZ-2tL (Bugtraq)
討論串 (同標題文章)
完整討論串 (本文為第 27 之 44 篇):
文章代碼(AID): #1AvZ-2tL (Bugtraq)