suid-binary vulnerabilities
suid-binary vulnerabilities
Posted Oct 29, 2010 13:41 UTC (Fri) by marcH (subscriber, #57642)In reply to: suid-binary vulnerabilities by kees
Parent article: Two glibc vulnerabilities
> Why? If this is about whole-system security, there will still be binaries with CAP_SETUID (su, sudo, newrole, seunshare, etc).
"Let's not bother making the windows more secure, because the front door sucks anyway".
Actually, let's bother. Because it's progress:
- progress towards the entire perimeter being finally secured.
- some malware knows only about windows. Being hacked once a month is progress compared to twice.
> It absolutely reduces the attack surface in general,...
Agreed!