[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [LCFC] templates://nethack/{nethack-common.templates}

Esko Arajärvi wrote:
> + your own NetHack levels and dungeons. The "recover" will be run every time the system
>   boots, if there are any auto-save files available.

Fair enough.

>   Recover is traditionally installed with the "setgid" bit (group "games").
> + This allows players to recover their save files, should NetHack crash or
> + their connection drop mid-game. However, this leaves the Nethack's save
> + directory world-writable and makes possible both cheating and messing up
> + other players.

s/the Nethack's save directory/NetHack's save directory/

"Leaves it world-writeable" would imply that the a+w bit is set.  It
doesn't do that, does it?  It just lets anybody run something that
can (in the course of its duties) write to that directory.  Are
there known recover exploits that let users modify save files, or is
this a "hypothetically possible"?
JBR	with qualifications in linguistics, experience as a Debian
	sysadmin, and probably no clue about this particular package

Reply to: