tech-security archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: hardlinks to setuid binaries
On Sun, Mar 27, 2022 at 01:47:44PM -0400, Thor Lancelot Simon wrote:
> Even better, imagine requiring an attribute to be set on a directory
> in order to _allow_ it to contain setuid executables. Or device nodes.
> Wouldn't that, in general, be safer and better than trying to decide all
> the places where such things should _not_ be allowed?
That is a good idea...
--
David A. Holland
dholland%netbsd.org@localhost
Home |
Main Index |
Thread Index |
Old Index