oss-sec mailing list archives

Re: Fw: Security risk of vim swap files


From: Kurt H Maier <khm () sciops net>
Date: Tue, 31 Oct 2017 11:10:51 -0700

On Tue, Oct 31, 2017 at 10:54:08AM -0700, Tim wrote:

Sure, you can argue that maybe some systems should ignore these files,
block access, etc, but it is pretty absurd to expect every other piece
of software in the universe to work around very unsafe defaults of text
editors.  

It's also fairly absurd to insist that people can run whatever program
they want, wherever they want, on a production web server, without being
familiar enough with the program to understand the risks.

Anyone who edits files in the deployment path with an insufficient
education is going to have problems, and not having noswapfile set is
the least of them.

khm


Current thread: