[Full-Disclosure] Re[2]: hard links on Linux create local DoS vulnerability and security problems
3APA3A
3APA3A at SECURITY.NNOV.RU
Tue Nov 25 17:32:45 GMT 2003
Dear Bruno Lustosa,
--Monday, November 24, 2003, 9:25:37 PM, you wrote to bugtraq at securityfocus.com:
BL> Just checked this on 2.6.0-test9, and it will not work.
BL> When you create a hard link to a setuid or any other file, it will
BL> inherit the same owner and mode of the original. However, if the
BL> original file is changed (owner, group, mode, or content), the link will
BL> reflect those changes as well.
No, if original file is removed and new one is created with same name.
--
~/ZARAZA
Да, ему чертовски повезло. Эх и паршиво б ему пришлось если бы он выжил! (Твен)
Full-Disclosure is hosted and sponsored by Secunia.