Bugtraq mailing list archives

Re: Cobalt RaQ 3 security hole?


From: wichert () CISTRON NL (Wichert Akkerman)
Date: Sat, 22 Jul 2000 14:40:45 +0200


Previously Kurt Seifried wrote:
Wouldn't it be a LOT more secure if the webserver ran as nobody and the
scripts that needed to run as root, well ran as root (and had properly
paranoid input checking).

One could use userv here to interact with the tools that need to be root,
that should improve things majorly.

Description: `user services' - program call across trust boundaries
 userv allows one program to invoke another when only limited trust
 exists between them.  It is a tool which can be used to avoid having
 to give other system services root privilege, and which allows users
 to more securely have programs provide services to others.

Wichert.

-- 
  _________________________________________________________________
 / Generally uninteresting signature - ignore at your convenience  \
| wichert () wiggy net                   http://www.liacs.nl/~wichert/ |
| 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |


<HR NOSHADE>
<UL>
<LI>application/pgp-signature attachment: stored
</UL>


Current thread: