FAQ Search Today's Posts Mark Forums Read

» Linux Archive
Home
New Posts
Search
FAQ


Go Back   Linux Archive > Redhat > Fedora User

 
 
LinkBack Thread Tools
 
Old 08-16-2008, 09:37 AM
Alan Cox
 
Default Can I create a link to an inode?

On Fri, 15 Aug 2008 22:22:16 +0000
Wayne Feick <waf@brunz.org> wrote:

> I'd consider it a security bug to allow a user to see any bytes beyond
> what was written to the file since:
>
> 1. Some ilesystems store multiple small files in the same block.
> 2. Some (most?) filesystems don't zero out blocks when they are
> reallocated.
>
> Either of the above could allow you to see things you shouldn't.

Which is why the kernel won't let you. What is on disk may vary but the
actual kernel interfaces deal with actual file sizes. Any holes you
create when extending it contain zeros

--
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
 
Old 08-16-2008, 05:06 PM
Wayne Feick
 
Default Can I create a link to an inode?

Thanks, Alan.

I figured that was the case, but it's good to get confirmation from
someone who knows.


On Sat, 2008-08-16 at 09:37 +0100, Alan Cox wrote:
> On Fri, 15 Aug 2008 22:22:16 +0000
> Wayne Feick <waf@brunz.org> wrote:
>
> > I'd consider it a security bug to allow a user to see any bytes beyond
> > what was written to the file since:
> >
> > 1. Some ilesystems store multiple small files in the same block.
> > 2. Some (most?) filesystems don't zero out blocks when they are
> > reallocated.
> >
> > Either of the above could allow you to see things you shouldn't.
>
> Which is why the kernel won't let you. What is on disk may vary but the
> actual kernel interfaces deal with actual file sizes. Any holes you
> create when extending it contain zeros


--
fedora-list mailing list
fedora-list@redhat.com
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
 

Thread Tools




All times are GMT. The time now is 06:23 AM.

VBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright ©2007 - 2008, www.linux-archive.org