[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Debian-User] Security Hole!??



On Sat, 2004-07-17 at 13:44, Didar Hussain wrote:
> Hi,
> 
> I just discovered that the permissions on /root and /home are
> "+rx" to "world". Any user can `cd' and `ls' to /root and 
> /home/<otheruser>!!!
> 
> Its NOT right! I'm using Stable. Should I complain to the
> security team?

On system installation there is a question:

"Do you want world readable home directories Yes/No"

Apparantly the answer to this question was Yes when the system was
installed.

Files that contain critical information in those homedirs are NOT
world-readable by default. Security by obscurity is not the answer.

-- 
Mark Janssen -- maniac(at)maniac.nl -- GnuPG Key Id: 357D2178
Unix / Linux, Open-Source and Internet Consultant @ SyConOS IT
Maniac.nl Unix-God.Net|Org MarkJanssen.org|nl SyConOS.com|nl

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: