[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

World writable pid and lock files.



Hello!

I imagine why files listed below have 666 file mode bits set:
/var/run/checkers.pid
/var/run/vrrp.pid
/var/run/keepalived.pid
/var/run/starter.pid
/var/lock/subsys/ipsec

Files are created during startup of ipsec (pluto) and keepalived deamons.

I think thar leaving them world writable is security hole. For example delete or change of its content could confuses monit watching them running and restarting when they die.

Regards.

--
helpermn


Reply to: