Difference in Ultrix (uucp/uu{en,de}code)
Carl S. Gutekunst
csg at pyramid.UUCP
Thu Mar 6 07:38:56 AEST 1986
In article <2766 at ukma.UUCP> david at ukma.UUCP (David Herron, NPR Lover) writes:
>For some reason uu{en,de}code are owned by uucp and set[ug]id
>to boot! WHY?????
> ...
>Fortunately this isn't a security hole.
Ah, but it is. uuencode and uudecode are typically owned by uucp, but NOT
set[ug]id. If they are, anyone can use them to read L.sys, USERFILE, etc.
--
Carl S. Gutekunst {allegra,cmcl2,decwrl,hplabs,topaz,ut-sally}!pyramid!csg
Pyramid Technology Corp, Mountain View, CA +1 415 965 7200
More information about the Comp.unix.wizards
mailing list