Re: [linux-security] vixie cron 3.0.1 continued

From: Cristian Gafton (gaftonat_private)
Date: Wed Feb 11 1998 - 01:19:29 PST

  • Next message: Sebastian Andersson: "Re: www-sql cgi prog overrides .htaccess restrictions."

    On Thu, 5 Feb 1998, [UNKNOWN-8BIT] Micha³ Zalewski wrote:
    
    > The problem with vixie cron is wider (and more funny) than I expected.
    > Here's my proggy which allows hiding files of any kind and size into
    > crontab entries (remember, quota is ignored ;-):
    
    This problem can be easily corrected, at least on Red Hat Linux systems,
    were every user have it's own group. vixie cron will install the crontab
    file with ownership root.usergroup.
    
    Installing group quotas for the partiotion /var/spool/cron resides on will
    solve the problem.
    
    I don't know about other linux systems, but at least on Red Hat the
    user-hroup scheme is proving to be useful in this case :-)
    
    Best wishes,
    
    Cristian
    --
    ----------------------------------------------------------------------
    Cristian Gafton   --   gaftonat_private   --   Red Hat Software, Inc.
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     UNIX is user friendly. It's just selective about who its friends are.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:42:28 PDT