View Single Post
  #1  
Old 2nd November 2010, 23:09
Norman Norman is offline
HowtoForge Supporter
 
Join Date: May 2006
Posts: 240
Thanks: 0
Thanked 16 Times in 14 Posts
Default Security question (best practise)

I noticed /var/log/ispconfig/cron.log is created as -rw-rw-rw-
Shouldn't it be -rw-r--r-- ?

(Just writable by root)
It'd be pretty bad if someone else writes or tampers with it and it is accidently executed by root using another shell or bypassing the no no execute chmod on it.
__________________
http://www.xh.se
Reply With Quote
Sponsored Links