[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

restricting /dev/vc/* to root.tty 660



Hi

devfs users currently have /dev/vc/* owned by root.tty but mode
666, which poses a security risk i'm said. In any event just
cating /dev/vc/0 has interesting effects, and is kind of a DoS
attack ...

Maybe the security team wants to publish an advisory, I have no
idea if this can be used for password sniffing or such.

People who need to access those should be added to the tty
group.

If this is a problem, let me know please.

ciao, 2ri
-- 
Help securing email, spread GPG, clearsign all mail. http://www.gnupg.org
.
Procter & Gamble, for example, uses an SGI system to study the
aerodynamics of Pringle's potato chips, Snell said. The chips move
along a conveyor belt so fast that they actually take flight.
	-- SGI press release regarding the Origin 3900

Attachment: signature.asc
Description: Digital signature


Reply to: