Full Disclosure mailing list archives
Re: Re: Linux kernel source archive vulnerable
From: "Chris Umphress" <umphress () gmail com>
Date: Tue, 12 Sep 2006 14:57:04 -0700
On 9/12/06, coderpunk <coderpunk () gmail com> wrote:
> >> The standard recommendation is to never compile > >> the kernel as root. > >> > > Which obviously doesn't help you when a non-root user edits the > > kernel, you compile it as 'jerry' but still have to install it as > > 'root'. You're still hosed. > > Geez, of course not. Unpacking the kernel as non-root honors umask. > Problem solved. > It would help to 'info tar' before posting... That assumes a proper umask. The kernel source should not depend on the end user's umask being setup properly.
Is it the kernel developers' fault if your umask is extremely lax for a normal user? If it is lax, security of the kernel source isn't your only problem.... Security in general is. -- Chris Umphress <http://daga.dyndns.org/> _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Re: tar alternative, (continued)
- Re: Re: tar alternative Tim (Sep 09)
- Re: Re: tar alternative darren kirby (Sep 09)
- Re: Re: tar alternative Tim (Sep 09)
- Re: tar alternative Aaron Gray (Sep 15)
- Re: tar alternative Tim (Sep 20)
- Re: tar alternative Jon Hart (Sep 20)
- Re: tar alternative Tonnerre Lombard (Sep 20)
- Re: Linux kernel source archive vulnerable Joe Feise (Sep 11)
- Re: Linux kernel source archive vulnerable coderpunk (Sep 12)
- Re: Re: Linux kernel source archive vulnerable Chris Umphress (Sep 12)
- Re: Linux kernel source archive vulnerable Schanulleke (Sep 15)
- Re: Linux kernel source archive vulnerable Troy Cregger (Sep 22)