Complete.Org: Mailing Lists: Archives: freeciv-dev: May 1999:
Re: [Freeciv-Dev] running civserver as root
Home

Re: [Freeciv-Dev] running civserver as root

[Top] [All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index] [Thread Index]
To: David Pfitzner <dwp@xxxxxxxxxxxxxx>
Cc: freeciv-dev@xxxxxxxxxxx
Subject: Re: [Freeciv-Dev] running civserver as root
From: Tony Stuckey <stuckey@xxxxxxxxxxxxxxxxx>
Date: Mon, 17 May 1999 10:43:02 -0500

On Mon, May 17, 1999 at 11:07:28PM +1000, David Pfitzner wrote:
> What I would like to know from freeciv-dev is whether there are
> any systems which currently run freeciv which may have problems
> with this patch, and whether there is anything we can/should
> do for such systems...
> 
> (Eg, particularly some unnamed systems where the user is
> effectively always "root"... Not that I think we should "dumb"
> freeciv down for such cases, but if we can readily accommodate 
> everyone...)

        MacOS and Windows and probably AmigaOS don't have getuid() style
calls.  That's not a "currently run".
        The more serious argument is about set-GID installations.  Should
freeciv be set-GID to a group like games, people could break into that
entire permissions set.
        Generally, this won't allow anything more than editing save files,
but it could possibly lead to account compromise.
-- 
Anthony J. Stuckey                              stuckey@xxxxxxxxxxxxxxxxx
"When I was young, the sky was filled with stars.
 I watched them burn out one by one."  -Warren Zevon

[Prev in Thread] Current Thread [Next in Thread]