Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Focus on Sun
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Sun Application Server Drop Privs Apr 26 2007 10:54AM
Alexander Klimov (alserkli inbox ru)
On Wed, 25 Apr 2007, haim [howard] roman wrote:
> Regarding (b), even if you run the server as root, you can change the
> owners &/or groups of the files so that non-root users can change them.

It may happen that controlling configuration files is enough to force
the application to do nasty things ...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus