Re: hardlinks.... sucks... ;-(

kwrohrer@enteract.com
Mon, 29 Dec 1997 05:04:46 -0600 (CST)


And lo, Yuri Kuzmenko saith unto me:
> Disabling of hardlink for non-readable file not help for this situation ;-( I
> will create the patch for disable user hardlinks for not-owned files. But
> there is _UGLY_ patch. I look for better solution. Help me, pls.
Less stupidity on the part of the sysadmins? (I can't think of a reason
to chown -R anything in /tmp, or anything in the home directory of a user
who's already been created...) Not leaving luser-writable directories
in the root partition (presumably /tmp would be a symlink to /var/tmp)
would also help. I didn't see how your security hole worked until I
stopped trying to think *why* root would do what you say he'd do.

Keith (locking a fellow luser over quota, now...)