Re: Separate tmp-dir for every user?
On Mon, Dec 01, 2008 at 05:24:12PM +0100, Paul van der Vlis wrote:
> Marcin Owsiany schreef:
> > On Mon, Dec 01, 2008 at 03:12:29PM +0100, Paul van der Vlis wrote:
> >> Hello,
> >>
> >> I am installing a new shared hosting server, and I would like to know
> >> how important it is to have a seperate tmp-dir for every user.
> >>
> >> What are the disadvantages/risks of a shared tmp-dir?
> >
> > Can you really elliminate the need for a shared /tmp? I guess you would
> > be really lucky not to come across an application which has /tmp
> > hardcoded and does not consult $T{E,}MPDIR
> >
> > As for the risks, the biggest is probably the possibility of having a
> > symlink attack vulnerability in one of your applications.
>
> But this is then a bug in the application, isn't it?
Yes, but it's like bashisms. You learn about them the hard way :-)
--
Marcin Owsiany <porridge@debian.org> http://marcin.owsiany.pl/
GnuPG: 1024D/60F41216 FE67 DA2D 0ACA FC5E 3F75 D6F6 3A0D 8AA0 60F4 1216
Reply to: