oss-sec mailing list archives
Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022
From: Jeffrey Walton <noloader () gmail com>
Date: Wed, 7 Oct 2020 22:09:43 -0400
On Wed, Oct 7, 2020 at 3:20 PM Jeremy Stanley <fungi () yuggoth org> wrote:
On 2020-10-07 21:00:35 +0300 (+0300), Georgi Guninski wrote:https://lists.debian.org/debian-security/2020/10/msg00000.html === /home/loser is with permissions 755, default umask 0022 on multiuser machines this sucks much.It's tradition that on multi-user systems, users would want to share data with one another and also serve content from their home directories in Web sites. Further, it's not at all uncommon for sysadmins to not understand or consider the system defaults when making deployment decisions and failing to secure sensitive files. As a long-time Debian user myself, I agree that this default is showing its age, and can represent a risk for operators who overlook it.
Microsoft has an elegant solution with Bypass Traverse Checking (SeChangeNotifyPrivilege). It allows an admin to deny access to /home/loser, but allow access to /home/loser/www. Instead of a permission check working down the hierarchy, just the www object is checked. Jeff
Current thread:
- Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Georgi Guninski (Oct 07)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Jeremy Stanley (Oct 07)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Noel Kuntze (Oct 07)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Brian May (Oct 07)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Solar Designer (Oct 12)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Kurt H Maier (Oct 12)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Jeffrey Walton (Oct 12)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Brian May (Oct 12)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Russ Allbery (Oct 12)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Jeremy Stanley (Oct 07)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Eli Schwartz (Oct 13)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Seth Arnold (Oct 07)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Bob Friesenhahn (Oct 08)
- Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022 Seth Arnold (Oct 08)