Re: /proc filesystem allows bypassing directory permissions on L
On Mon, Oct 26, 2009 at 9:01 AM, Tony Finch <dot@dotat.at> wrote:
> Attacker uses openat() to open and modify the "private" file.
At least with Linux 2.6.18, you still need +x permission on the
directory to access its contents using openat(2).
討論串 (同標題文章)
完整討論串 (本文為第 29 之 44 篇):