Bugtraq mailing list archives
.lsof_dev_cache
From: de5 () sws5 CTD ORNL GOV (Dave Sill)
Date: Fri, 25 Aug 1995 08:00:45 -0400
»This file appears to hold pointers into device files, memory maps, etc. »which lsof reads the next time around. It could be very dangerous since »lsof normally runs as root. Please tell me I'm wrong and it's not a hazard.
From the lsof man page:
The device cache file is stored by default in /tmp with read and write permission for owner, group, and user, so any lsof call can access or rebuild it. (You can change the device cache file path with the optional path suffix of the b, r, and u functions.) Lsof can detect that the file has been accidentally or maliciously modi- fied by several sanity checks, including a sixteen bit Cyclic Redundancy Check (CRC) sum of the file's contents. When lsof senses something wrong with the file, it will attempt to remove the current one and create a new copy. The only risk I see is that someone could edit out certain devices. The "-D i" option tells lsof to ignore the cache completely. -Dave
Current thread:
- Re: DO NOT USE THAT PATCH (Re: IP firewalling bugs) der Mouse (Aug 23)
- Re: DO NOT USE THAT PATCH (Re: IP firewalling bugs) Tom Fitzgerald (Aug 23)
- -rw-rw-rw- 1 root 8025 Aug 24 04:10 Dr. Frederick B. Cohen (Aug 24)
- Security Mailing Lists Christopher Klaus (Dec 09)
- Re: -rw-rw-rw- 1 root 8025 Aug 24 04:10 /tmp/.lsof_dev_cache Vic Abell (Aug 24)
- .lsof_dev_cache Dave Sill (Aug 25)
- Re: -rw-rw-rw- 1 root 8025 Aug 24 04:10 Darren Reed (Aug 25)
- Re: -rw-rw-rw- 1 root 8025 Aug 24 04:10 Dave Roberts (Aug 29)
- Re: -rw-rw-rw- 1 root 8025 Aug 24 04:10 Vic Abell (Aug 30)
- Re: -rw-rw-rw- 1 root 8025 Aug 24 04:10 /tmp/.lsof_dev_cache Scott Barman (Aug 25)
- Re: -rw-rw-rw- 1 root 8025 Aug 24 04:10 /tmp/.lsof_dev_cache Vic Abell (Aug 28)
- [8lgm]-Advisory-22.UNIX.syslog.2-Aug-1995 [8LGM] Security Team (Aug 28)
- Re: [8lgm]-Advisory-22.UNIX.syslog.2-Aug-1995 Rob J. Nauta (Aug 29)
- Re: [8lgm]-Advisory-22.UNIX.syslog.2-Aug-1995 Jay 'Whip' Grizzard (Aug 29)
- Re: [8lgm]-Advisory-22.UNIX.syslog.2-Aug-1995 Perry E. Metzger (Aug 29)
- SunOS syslog.c replacement Matthew Donaldson (Aug 30)