[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]
Re: bash 3.1 update
- From: Peter Bieshaar <peter bieshaar gmail com>
- To: russell coker com au, Development discussions related to Fedora Core <fedora-devel-list redhat com>
- Cc:
- Subject: Re: bash 3.1 update
- Date: Thu, 5 Jan 2006 14:00:09 +0100
agree to all above,
if I create a package (normally under Solaris, sorry I'm a Solaris person and spying on you :) ) I make the permissions as strict as possible.
IMHO there is normally no reason WHY a binary executable should be readable. I checked my laptop (FC4) and saw the permissions indeed 755 for bash. A 111 (---x--x--x) is normally enough for a binary. In very rare cases a suid/sgid should (not) be set (see my grey hair).The kernel will still read it though magic and kernel drivers. Script permissions is another story off-course.
My strategy is to make it as difficult as much to myself and try to secure the system from bottom-up. In other words, I should re-define permissions as strict as possible in the rpm. But that is another discussion.
This might be a point for FC6??
--
Peter Bieshaar
NL(0)6 29577255
[Date Prev][Date Next] [Thread Prev][Thread Next]
[Thread Index]
[Date Index]
[Author Index]