Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: "Daniel Johnson" <danieljohnson@xxxxxxxxxxxx>
- Date: Wed, 17 May 2006 18:50:08 -0400
"GreyCloud" <mist@xxxxxxxxxxx> wrote in message
news:vIOdnQGZbf-2_vfZRVn-hA@xxxxxxxxxxxxxx
Daniel Johnson wrote:[snip]
Well, I will snip the rest as we should ignore the rest as it is totally
irrelevant eh?
I quite agree!
The answer has to do with how processes are started, inherit permissions
from the uid/gid, etc.
I don't think so.
Everything coming into any UNIX box thru a browser is automatically set
to read only.
This is not true. Try it yourself; download a text file
and then check to see if you can edit it.
Even if it were true, it woudl not help; read only
programs can be executed, and once running
can wreak havok. There is no need to alter anything
that was downloaded.
Now you tell me how a foreign program is going to inherit the uid/gid of a
user process in order to run or install malware?
If it does not have the setuid bit set, then it inherits the uid/gid
of the process that starts it. The Finder process or the browser's
process or the Dashboard process might do this; all of these
have the user's uid and gid.
Quite simple.
.
- Follow-Ups:
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: GreyCloud
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Josh McKee
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- References:
- New Patch Fixes 43 Flaws In OS X, Many Serious
- From: John Slade
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Oxford
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Josh McKee
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Josh McKee
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Josh McKee
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Josh McKee
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Tim Murray
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Josh McKee
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: GreyCloud
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Daniel Johnson
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: GreyCloud
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Daniel Johnson
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: GreyCloud
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Daniel Johnson
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: sav
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: Daniel Johnson
- Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- From: GreyCloud
- New Patch Fixes 43 Flaws In OS X, Many Serious
- Prev by Date: Re: AOPA Flight planner is a great piece of software
- Next by Date: Re: Flightsoft runs fine on XP
- Previous by thread: Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- Next by thread: Re: New Patch Fixes 43 Flaws In OS X, Many Serious
- Index(es):
Relevant Pages
|