From: Tom Gilbert Date: 2002-09-13T23:46:25+09:00 Subject: Re: RubyInline 1.0.4 Released! (fwd) --kvUQC+jR9YzypDnK Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable * bbense+comp.lang.ruby.Sep.12.02@telemark.stanford.edu (bbense+comp.lang.r= uby.Sep.12.02@telemark.stanford.edu) wrote: > >That's why a group writable home directory is bad. I can go in and creat= e a > >.rhosts file that allows me to become you, and get you in trouble. > > >=20 > - Yes, if your home dir is group writeable you have a lot more > problems than trojan ruby-inline files.... But if say /home > was group writeable, and I check ownership of the files I don't > see how there is an attack unless the OS allows ordinary users > to chown files. I know this was possible in older unix > versions, but I don't know of any current unix OS's that allow > this. I guess I should read what POSIX has to say about the > matter.=20 I shouldn't worry too much about chown. If a directory is group writeable and I'm in that group, I can delete everything in that directory and replace it with whatever I like. I think that's the important problem that certain programs check for. Tom. --=20 .^. .-------------------------------------------------------. /V\ | Tom Gilbert, London, England | http://linuxbrit.co.uk | /( )\ | Open Source/UNIX consultant | tom@linuxbrit.co.uk | ^^-^^ `-------------------------------------------------------' --kvUQC+jR9YzypDnK Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE9gfo16fJVg2PPi5URArktAJ0QIZGfSGvetfPNagBj2ESBFySzRgCgnipG n8dFJCublfsAXZ4TolFrTTo= =qyzh -----END PGP SIGNATURE----- --kvUQC+jR9YzypDnK--