<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-32090778.post6999011974643826587..comments</id><updated>2009-03-19T09:56:57.892-06:00</updated><title type='text'>Comments on Funtoo by Daniel Robbins: Baselayout /etc/shadow local vulnerability</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.funtoo.org/feeds/6999011974643826587/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default'/><link rel='alternate' type='text/html' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html'/><author><name>Daniel Robbins</name><uri>http://www.blogger.com/profile/09134601055128665246</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-32090778.post-1200850507764280801</id><published>2009-03-19T09:14:00.000-06:00</published><updated>2009-03-19T09:14:00.000-06:00</updated><title type='text'>Thanks for this Daniel, much appricate the work yo...</title><content type='html'>Thanks for this Daniel, much appricate the work you are doing on funtoo</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/1200850507764280801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/1200850507764280801'/><link rel='alternate' type='text/html' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html?showComment=1237475640000#c1200850507764280801' title=''/><author><name>Brett Royles</name><uri>http://www.blogger.com/profile/17540448549785771548</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html' ref='tag:blogger.com,1999:blog-32090778.post-6999011974643826587' source='http://www.blogger.com/feeds/32090778/posts/default/6999011974643826587' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-32090778.post-4771601107214543901</id><published>2009-03-05T23:19:00.000-07:00</published><updated>2009-03-05T23:19:00.000-07:00</updated><title type='text'>I've added a first round of security checks that w...</title><content type='html'>I've added a first round of security checks that will detect if /etc/shadow and a few other critical files and directories have incorrect permissions.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/4771601107214543901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/4771601107214543901'/><link rel='alternate' type='text/html' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html?showComment=1236320340000#c4771601107214543901' title=''/><author><name>Daniel Robbins</name><uri>http://www.blogger.com/profile/09134601055128665246</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06112337746230715438'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html' ref='tag:blogger.com,1999:blog-32090778.post-6999011974643826587' source='http://www.blogger.com/feeds/32090778/posts/default/6999011974643826587' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-32090778.post-3795358235622671719</id><published>2009-03-05T19:08:00.000-07:00</published><updated>2009-03-05T19:08:00.000-07:00</updated><title type='text'>Good you're keeping and eye on things.  Thanks!</title><content type='html'>Good you're keeping and eye on things.  Thanks!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/3795358235622671719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/3795358235622671719'/><link rel='alternate' type='text/html' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html?showComment=1236305280000#c3795358235622671719' title=''/><author><name>linuxtidbits</name><uri>http://linuxtidbits.wordpress.com/</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html' ref='tag:blogger.com,1999:blog-32090778.post-6999011974643826587' source='http://www.blogger.com/feeds/32090778/posts/default/6999011974643826587' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-32090778.post-7305071436803627638</id><published>2009-03-04T12:15:00.000-07:00</published><updated>2009-03-04T12:15:00.000-07:00</updated><title type='text'>You are a Crack! ;)</title><content type='html'>You are a Crack! ;)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/7305071436803627638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/7305071436803627638'/><link rel='alternate' type='text/html' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html?showComment=1236194100000#c7305071436803627638' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html' ref='tag:blogger.com,1999:blog-32090778.post-6999011974643826587' source='http://www.blogger.com/feeds/32090778/posts/default/6999011974643826587' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-32090778.post-4896135015509053602</id><published>2009-03-02T20:41:00.000-07:00</published><updated>2009-03-02T20:41:00.000-07:00</updated><title type='text'>Fixed. Thanks :)</title><content type='html'>Fixed. Thanks :)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/4896135015509053602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/4896135015509053602'/><link rel='alternate' type='text/html' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html?showComment=1236051660000#c4896135015509053602' title=''/><author><name>Daniel Robbins</name><uri>http://www.blogger.com/profile/09134601055128665246</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06112337746230715438'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html' ref='tag:blogger.com,1999:blog-32090778.post-6999011974643826587' source='http://www.blogger.com/feeds/32090778/posts/default/6999011974643826587' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-32090778.post-4322270310606136681</id><published>2009-03-02T20:21:00.000-07:00</published><updated>2009-03-02T20:21:00.000-07:00</updated><title type='text'>actually chmod 0600 /etc/shadow (like what you cha...</title><content type='html'>actually chmod 0600 /etc/shadow (like what you changed in the ebuild) is appropriate.&lt;BR/&gt;&lt;BR/&gt;in theory chmod ugo-r could leave write or executable permissions on files that shouldn't have it. also why do you want to remove read from the 'user' or 'owner' permission (e.g the u in ugo). given that it's owned by root it doesn't affect a thing, but in a sense that's still improper.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/4322270310606136681'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/32090778/6999011974643826587/comments/default/4322270310606136681'/><link rel='alternate' type='text/html' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html?showComment=1236050460000#c4322270310606136681' title=''/><author><name>xenoterracide</name><uri>http://www.blogger.com/profile/08185254298048097278</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.funtoo.org/2009/03/baselayout-etcshadow-local.html' ref='tag:blogger.com,1999:blog-32090778.post-6999011974643826587' source='http://www.blogger.com/feeds/32090778/posts/default/6999011974643826587' type='text/html'/></entry></feed>