Path: utzoo!utgpu!news-server.csri.toronto.edu!bonnie.concordia.ca!thunder.mcrcim.mcgill.edu!snorkelwacker.mit.edu!apple!usc!samsung!sol.ctr.columbia.edu!cica!news.cs.indiana.edu!ux1.cso.uiuc.edu!mp.cs.niu.edu!rickert From: rickert@mp.cs.niu.edu (Neil Rickert) Newsgroups: news.software.b Subject: Re: Restricting article posting with C News... Message-ID: <1991Jan11.002040.25338@mp.cs.niu.edu> Date: 11 Jan 91 00:20:40 GMT References: <1991Jan9.201748.4682@zoo.toronto.edu> <3113@crdos1.crd.ge.COM> <1991Jan10.213702.9298@zoo.toronto.edu> Organization: Northern Illinois University Lines: 21 In article <1991Jan10.213702.9298@zoo.toronto.edu> henry@zoo.toronto.edu (Henry Spencer) writes: >In article <3113@crdos1.crd.ge.COM> davidsen@crdos1.crd.ge.com (bill davidsen) writes: >> Relaynews or mail or whatever, yes, but at least with B news (on my >>site) a lot of the news software is setuid news and a user won't be able >>to run his (her) own copy. > >This is one small disadvantage of using a lot of shell files: in general >they have to be readable, and making them setuid isn't entirely safe, so >they're open to being copied and modified by users. Perhaps my brain had a core dump, or something, but I don't understand what all the fuss is about. C-news doesn't work (for posting articles) without invoking some setuid programs such as 'relaynews' and 'newsspool'. If the group permissions are used to control who can search $NEWSBIN/relay and $NEWSBIN/input, won't the problem be easily solved? -- =*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*= Neil W. Rickert, Computer Science Northern Illinois Univ. DeKalb, IL 60115 +1-815-753-6940