Re: Security Anti Symlink Attack Patch for 2.1.71

Robert Bihlmeyer (robbe@orcus.priv.at)
09 Dec 1997 09:03:43 +0100


Hi,

>>>>> On Mon, 8 Dec 1997 11:51:57 +0100
>>>>> Wolfgang Walter <wolfgang.walter@stusta.mhn.de> said:

Wolfgang> I agree, it would be fine to see that as a config option,
Wolfgang> or even better as sysctl-tunable option. I think it would
Wolfgang> be even finer if it can be switched on only for certain +t
Wolfgang> directories. One possibility would be if kernel checks if
Wolfgang> there is a file owned by the directory-owner called
Wolfgang> .restricted_sym or so.

Ugh, the last option is rather ugly. Better permit something like:

echo /tmp:/var/tmp:/sdd1/tmp > /proc/sys/fs/restricted_symlinks

The list of affected directories should be rather short (2 or 3 dirs)
on normal setups.

Robbe

-- 
Robert Bihlmeyer	reads: Deutsch, English, MIME, Latin-1, NO SPAM!
<robbe@orcus.priv.at>	<http://stud2.tuwien.ac.at/~e9426626/sig.html>