[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: cons.saver exploit and /dev/vcsa* owner



On Tue, Nov 14, 2000 at 01:23:09PM -0800, Philip Brown wrote:
> 
> Solaris does a similar this too.
> In fact, Solaris has a nice CONFIG FILE to deal with this sort of thing:
> 
> /etc/logindevperm
> 
> which has a list of /dev/xxx names to chown, and the appropriate umask to
> set, if someone is logged in on console.
> 
> I think that's a good idea.

depends, do the /dev/vcs* devices get a hangup when the user logs out
like /dev/tty* do?  otherwise users could play the same games as they
can with audio devices and block devices to retain access even after
its been chowned back to root or someone else.   (keeping open file
descriptors) 

-- 
Ethan Benson
http://www.alaska.net/~erbenson/

Attachment: pgpRMVlvKqHBj.pgp
Description: PGP signature


Reply to: