Home page logo

bugtraq logo Bugtraq mailing list archives

Re: /proc filesystem allows bypassing directory permissions on Linux
From: Matthew Dempsky <matthew () dempsky org>
Date: Mon, 26 Oct 2009 15:48:22 -0700

On Mon, Oct 26, 2009 at 9:01 AM, Tony Finch <dot () dotat at> wrote:
Attacker uses openat() to open and modify the "private" file.

At least with Linux 2.6.18, you still need +x permission on the
directory to access its contents using openat(2).

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]