Re: strace security <feature>

Kevin George (kevin@acid.raindrop.net)
Wed, 29 Dec 1999 15:28:06 -0800 (PST)


On Wed, 29 Dec 1999, Richard B. Johnson wrote:

> Hello security gurus,
>
> This may not be a kernel issue, but `strace` interacts with it so
> here is the frightening thing:
>
> It is possible for an ordinary user to use `strace` (which by default
> runs SUID-root), to copy a password file to /etc.
^^^^^^^^^^^^^^

Ummm, what distribution is it suid on? I've never seen it setuid.

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/