|
|
|
|
|
by viraptor
3276 days ago
|
|
Strict validation. If some option is not valid, fail loudly. And he still fails to acknowledge this is a security issue. Here's a scenario for you: You're running a SaaS which spawns restricted demons/containers per customer, separating the users by assigning them local user accounts. One day, user "0zero" registers and their account has access to your whole environment. Would you expect this? Would you not classify this as a security issue? |
|
* http://jdebp.eu./Softwares/nosh/guide/setuidgid.html
* http://cr.yp.to/daemontools/setuidgid.html
* http://untroubled.org/daemontools-encore/setuidgid.8.html
... as is documented in their user manuals, resulting in ...
... the 0day service from the headlined bug report failing to start.