[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: file/directory name usage under /



Vincent Lefevre wrote:
> Bob Proulx wrote:
> > Vincent Lefevre wrote:
> > > Is it OK that anyone who has a write access in this directory can
> > > become root on the machine?
> > 
> > That question is ambiguous.  Do you mean that someone who can write to
> > /foo can use that to become root?
> 
> Yes. Say, during an upgrade of the system or package installation,
> some given file /foo/bar gets executed under root (thanks to ldd).

Please say more?  I know of no way that having write to /foo will give
priviledge escalation.

Bob

Attachment: signature.asc
Description: Digital signature


Reply to: