On Thu, Feb 21, 2013 at 06:25:07PM +0000, Steven Chamberlain wrote: > Hi, > > On 21/02/13 18:19, Henri Salo wrote: > > After installing nginx in squeeze directory /var/log/nginx is world > > readable as > > reported in http://www.openwall.com/lists/oss-security/2013/02/21/15 > > What about the permissions of the files themselves? > > Logs that have been rotated are recreated by logrotate with mode -rw-r----- > > But I notice if nginx creates new a log file itself, it sets mode -rw-r--r-- > > Regards, > -- > Steven Chamberlain > [email protected]
As you said. For new files: -rw-r--r--, which in my opinion should be fixed. Do you agree? -- Henri Salo -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

