compress and setting owner/group

Ron Natalie ron at topaz.rutgers.edu
Tue Jul 12 01:26:25 AEST 1988


> Do 4bsd sites run compress as a setuid root program?

NO.  The ability for a random user to create files that end up
being owned by "me" is antisocial and should NOT be supported.
Too much reliance is put on the owner of the files to allow
users to do this.  For example, consider disk quotas.

> Is compress safe to install as a setuid root program?

Certainly NOT!

-Ron



More information about the Comp.unix.questions mailing list