Re: How to embed framework in app with setuid helper
Re: How to embed framework in app with setuid helper
- Subject: Re: How to embed framework in app with setuid helper
- From: Bill Cheeseman <email@hidden>
- Date: Sat, 15 Sep 2007 09:53:26 -0400
- Thread-topic: How to embed framework in app with setuid helper
on 2007-09-15 7:42 AM, Finlay Dobbie at email@hidden wrote:
> Well, your framework is probably writeable by non-root users, meaning
> that someone could go in and replace your framework with some
> malicious code, which would then be blindly loaded by your setuid
> binary and executed.
>
> Once you understand this, you should understand the solution.
I'm not sure I understand your hint. The embedded framework was indeed
read-write for all. But changing it to read-only for all yields the same
error.
--
Bill Cheeseman - email@hidden
Quechee Software, Quechee, Vermont, USA
www.quecheesoftware.com
PreFab Software - www.prefabsoftware.com
_______________________________________________
Cocoa-dev mailing list (email@hidden)
Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden