Security Issue with Cygwin

Lambeth Darwin dlambeth@darwinsdomain.com
Thu Jan 23 04:08:00 GMT 2003


To whom it may concern;

Not sure if you know this or not, but the default configuration with Cygwin allows any user to change to any directory on a W2K box and delete whatever files they want. I have installed it with the current default instructions and was able to logon as a regular domain user and cd to c: and delete or add files. That is a major issue. Let me know if there is something I missed.

Thank
Darwin L. Lambeth
dlambeth@darwinsdomain.com


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Bug reporting:         http://cygwin.com/bugs.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/



More information about the Cygwin mailing list