1 |
Apparently, though unproven, at 22:28 on Saturday 11 September 2010, Etaoin |
2 |
Shrdlu did opine thusly: |
3 |
|
4 |
> On Sat, 11 Sep 2010 15:35:58 -0500 Dale <rdalek1967@×××××.com> wrote: |
5 |
> > If they are accessible by a user, couldn't a user then edit or add |
6 |
> > something that would then cause a security problem? If they can edit |
7 |
> > them and no one know it, then root comes along and builds a shiney new |
8 |
> > kernel with a really nice security hole. |
9 |
> |
10 |
> This was actually a potential risk once upon a time: |
11 |
> |
12 |
> http://attrition.org/security/advisory/gobbles/GOBBLES-16.txt |
13 |
|
14 |
More like an actual risk all the time. Which is why: |
15 |
|
16 |
# ls -al /usr/src/ |
17 |
total 2 |
18 |
drwxr-xr-x 3 root root 136 2010-09-01 11:41 . |
19 |
drwxr-xr-x 17 root root 480 2010-08-23 01:44 .. |
20 |
-rw-r--r-- 1 root root 0 2008-06-17 19:37 .keep |
21 |
lrwxrwxrwx 1 root root 18 2010-09-01 11:30 linux -> linux-2.6.35-ck-r2 |
22 |
drwxr-xr-x 24 root root 1584 2010-09-01 02:12 linux-2.6.35-ck-r2 |
23 |
|
24 |
|
25 |
|
26 |
-- |
27 |
alan dot mckinnon at gmail dot com |