Path: utzoo!utgpu!news-server.csri.toronto.edu!bonnie.concordia.ca!uunet!stanford.edu!agate!ziploc!eps From: eps@toaster.SFSU.EDU (Eric P. Scott) Newsgroups: comp.sys.next Subject: Re: Preserving file ownerships on OD? Message-ID: <1782@toaster.SFSU.EDU> Date: 22 Jun 91 04:49:08 GMT References: <1991Jun20.220525.5015@ccu.umanitoba.ca> <1991Jun21.203134.7927@csus.edu> Reply-To: eps@cs.SFSU.EDU (Eric P. Scott) Organization: San Francisco State University Lines: 15 In article <1991Jun21.203134.7927@csus.edu> hoodr@syscube.ccs.csus.edu (Robert Hood) writes: >The problem you are running into is actually a security feature. How? By giving me READ and WRITE access to other people's data? Some feature. >Hypothetical situation: >(I wish) I own a NeXT. I have superuser (as well as any other user) access. >I create an optical disk with a setuid root shell (or any program). As long as the automounter sets the "nosuid" flag your argument doesn't hold. -=EPS=-