This is the mail archive of the cygwin@cygwin.com mailing list for the Cygwin project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: Security Issue with Cygwin


On Thu, 2003-01-23 at 11:48, Lambeth Darwin wrote:
> To whom it may concern;
> 
> Not sure if you know this or not, but the default configuration with Cygwin allows any user to change to any directory on a W2K box and delete whatever files they want. I have installed it with the current default instructions and was able to logon as a regular domain user and cd to c: and delete or add files. That is a major issue. Let me know if there is something I missed.

Thats the Microsoft default install that grants those permissions.
Cygwin doesn't affect permissions outside of the cygwin directory tree.

Rob
-- 
GPG key available at: <http://users.bigpond.net.au/robertc/keys.txt>.

Attachment: signature.asc
Description: This is a digitally signed message part


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]