Crossfire Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Setuid?????



On Sat, 12 Mar 1994, Kjetil Torgrim Homme wrote:

> You don't have to change the server, just change permissions:
> 
> chmod u+s bin/crossfire
> chmod -R go-rwx lib/maps
> 
> (change filenames to fit :-)
> 
> Do note that there _may_ be security leaks in Crossfire, and there's a
> chance someone can exploit it to remove files or similar. (I would not
> dare make CrossEdit setuid, for instance, but I haven't checked to see
> if my fears are justified.)

I would not dare also, because user can define the programs in
resources, what to run (selections "CrossFire","Reset").

///////////////////////// Petri Heinila /////////////////////////
email: Petri.Heinila@lut.fi
  www: <A HREF="http://www.lut.fi/~hevi/">Homepage</A>
 mail: Ainonkatu 2A
       53100 Lappeenranta
       Finland, Europe
  tel: (953) 574 3624