Re: GtkFileSelection security problem?
| From: | Ben Ramsey | Date: | Thu, 10 Jun 2004 04:01:51 +0000 |
| Subject: | Re: GtkFileSelection security problem? | ||
| References: | 1 2 | Groups: | php.gtk.dev php.gtk.general |
| Request: | Send a blank email to php-gtk-dev+get-628@lists.php.net to get a copy of this message | ||
Well, isn't that weird. So, if a root-owned file is in a directory that user has access to, it will allow user to delete it? I didn't know that because I had never tried to do it.
Thanks for the info.
James Cameron wrote:
But this is not unusual. It's doing exactly what the operating system lets it do. The directory ownership counts for more. Example: host:~$ touch test-file host:~$ ls -l test-file-- Regards, Ben Ramsey http://benramsey.com --------------------------------------------------- http://www.phpcommunity.org/ Open Source, Open Community Visit for more information or to join the movement. ----------------------------------------------------rw-r--r-- 1 user user 0 Jun 10 13:46 test-filehost:~$ su Password: host:/home/user# chown root:root test-file host:/home/user# exit exit host:~$ ls -l test-file-rw-r--r-- 1 root root 0 Jun 10 13:46 test-filehost:~$ rm test-file rm: remove write-protected regular empty file `test-file'? y host:~$