Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: BSD chfn bug (aka ssh quirks/killing thread)

Re: BSD chfn bug (aka ssh quirks/killing thread)

From: Blue Boar <BlueBoar_at_THIEVCO.COM>
Date: Tue, 28 Dec 1999 14:06:02 -0800

FARAZ JAMSHED wrote:
>
> >>In message <Pine.LNX.4.20.9912251656310.23074->>100000_at_pet.notbsd.org>
> >>"Stanislav N. Vardomskiy" writes:
> >>: This just *might* be a problem.
> >
> >Not the way you think. You have no control over the name of the file
> >created.
> >
> >Warner
>
> yes we could have control by setting the right UMASK settings...
>

The question posed was is there a way to get a file with the name you
want in /etc using the bug under discussion. Most folks (myself
included) fail to see how the umask setting helps with that. To
rename files, one has to have rights on the parent directory,
not the file itself.

So, if you've got an example of how umask helps, we'd love to
see it.

Other than that, we've all had our unix file permission refresher
for the week. People are starting to get nasty in their replies.
So, unless folks have some interesting technical points that
bring us closer to a security hole, I'm going to kill off
these threads.

                                        BB
Received on Dec 28 1999

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos