[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Should gcc be usable by world ?
Hi:
I see that gcc, g++, and other tools are usable by world (others). I was wondering if that is a bad idea as I read here: http://www.itworld.com/nl/lnx_sec/09242002/pf_index.html
that the slapper worm used gcc to compile it's exploit.
Excerpt: The worm requires gcc to compile the .bugtraq.c file. ....
Is it a good idea to change the permisions on the gcc tools to 750 ? I looked through the FreeBSD Handbook and could find no advice on this matter. Also, are there other tools that should not be available like strace? How can I find out which ones are potentially
exploitable?
Kind regards,
Jonathan
-
To unsubscribe, send email to majordomo@silug.org with
"unsubscribe silug-discuss" in the body.