On Wed, Jan 22, 2003 at 08:41:23AM +0100, Alexander Steinert wrote:
[ stupid advice snipped ]
> /usr/bin/tail /var/log/[^.]*
> will prevent
> sudo tail /var/log/../../etc/shadow
> but not
> sudo tail /var/log/apache/../../../etc/shadow
> :-(
Hrm, thanks for catching that.
> I have no better i
> > I allow read-access to all of /var/log. However, I also allow read
> > access to /etc/shadow:
> >
> > /usr/bin/tail /var/log/../../etc/shadow
> >
> > does work. How can I best restrict that? I've tried
>
>
> /usr/bin/tail/[^.]*
/usr/bin/tail /var/log/[^.]*
will prevent
sudo tail /var/log
On Tue, Jan 21, 2003 at 12:25:35PM +0100, martin f krafft wrote:
> when I allow something like this in sudo:
>
> /usr/bin/tail /var/log/*
>
> I allow read-access to all of /var/log. However, I also allow read
> access to /etc/shadow:
>
> /usr/bin/tail /var/log/../../etc/shadow
>
> does work
3 matches
Mail list logo