|
Message-ID: <CAOfWR+E5EBSOe5kbSFh2zwUXKAahDXi6Dpax6dr9FLVkT1pY3g@mail.gmail.com> Date: Sat, 21 Oct 2017 15:57:52 -0400 From: Robert Watson <robertcwatson1@...il.com> To: oss-security@...ts.openwall.com Subject: Re: CVE-2017-8805: Unsafe symlinks not filtered in Debian mirror script ftpsync Thank You for tolerating my questions. I've read the wikis and pages you've suggested, and am attempting to format this reply as required. Please advise if anything is still wrong. On Sat, Oct 21, 2017 at 6:58 AM, Solar Designer <solar@...nwall.com> wrote: > > > On Fri, Oct 20, 2017 at 11:08:14PM +0000, Robert Watson wrote: > > Okay, so a script adds a symlink to /etc/shadow or something else > > confidential. Unless they're root, what good does it do them? They can't > > read it. > > I think this specific question had already been addressed by Ben in: > > http://www.openwall.com/lists/oss-security/2017/10/18/12 > ... I didn't see how revealing configuration details was anything more than "security by obscurity" but that's not a discussion for this forum. Mea Culpa. > While we're at it, I also recommend that you avoid top-posting and > over-quoting. Here's how to format your messages better: Believe it or not, this is first occasion using the "Plain text" feature in the browser version of Gmail and editing the included text. Was using Google Inbox on a tablet before. I write programs. Really pretty naive when it comes to skillfully using software. Will use this in the future. Robert
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.