Re: unneeded information in sudo

From: Emad El-Haraty (elharatyat_private)
Date: Thu Jun 10 1999 - 12:02:04 PDT

  • Next message: Roche-Kelly, Edmund B.: "Re: useradd -p stores cleartext passwords / shadow-980724"

    On Wed, 9 Jun 1999, Samuel Mikes wrote:
    
    > >> "Bencsath" == Bencsath Boldizsar <boldiat_private> writes:
    > Bencsath> Sudo (debian , v1.5.6p2-2) tells anyone if a file exists or
    > Bencsath> not. It's not a very big problem, but when i set a
    > Bencsath> directory _not_ accessible to anyone but root, I want to
    > Bencsath> make sure, nobody knows what files are in it.  Both
    > Bencsath> executable and not executables- if there is no file: No
    > Bencsath> such file or directory, if it exists: permission denied if
    > Bencsath> not executable, You are not in sudoers if executable.
    >
    When configuring (at compile time) would setting --disable-path-info
    stop this problem?
    
    here is it's description:
      --disable-path-info
            Normally, sudo will tell the user when a command could not be found
            in their $PATH.  Some sites may wish to disable this as it could
            be used to gather information on the location of executables that
            the normal user does not have access to.
    
    
    
     Emad El-Haraty
     "The best thing about computers is that they fly around the room when you
      get real mad at them."
                        -- Joe Ely Carrales, III
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:49:08 PDT