Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CAOfWR+E5EBSOe5kbSFh2zwUXKAahDXi6Dpax6dr9FLVkT1pY3g@mail.gmail.com>
Date: Sat, 21 Oct 2017 15:57:52 -0400
From: Robert Watson <robertcwatson1@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2017-8805: Unsafe symlinks not filtered in
 Debian mirror script ftpsync

Thank You for tolerating my questions. I've read the wikis and pages
you've suggested, and am attempting to format this reply as required.
Please advise if anything is still wrong.


On Sat, Oct 21, 2017 at 6:58 AM, Solar Designer <solar@...nwall.com> wrote:
>
>
> On Fri, Oct 20, 2017 at 11:08:14PM +0000, Robert Watson wrote:
> > Okay, so a script adds a symlink to /etc/shadow or something else
> > confidential. Unless they're root, what good does it do them? They can't
> > read it.
>
> I think this specific question had already been addressed by Ben in:
>
> http://www.openwall.com/lists/oss-security/2017/10/18/12
> ...

I didn't see how revealing configuration details was anything more
than "security by obscurity" but that's not a discussion for this
forum. Mea Culpa.

> While we're at it, I also recommend that you avoid top-posting and
> over-quoting.  Here's how to format your messages better:

Believe it or not, this is first occasion using the "Plain text"
feature in the browser version of Gmail and editing the included text.
Was using Google Inbox on a tablet before. I write programs. Really
pretty naive when it comes to skillfully using software.

Will use this in the future.

Robert

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.