On Sat, 2006-02-18 at 13:37 +0200, Oleg Goldshmidt wrote:
> Omer Zak <[EMAIL PROTECTED]> writes:
>
>
> > However, when a directory is protected, then the files inside it are
> > protected as well.
>
> Not quite true.
>
> For instance, I just did a quick check. While the actual profile
> directory is 700, the upper level directories (e.g.,
> ~/.mozilla/firefox) are group-writeable. I have trivially replaced the
> contents of the profile while logged in as a different user. You do
> not want me to modify your bookmarks or history or cache, do you?
I made my statement after actually testing by trying to access files
under a 700 directory belonging to another user+group.
My setup of users and groups (in vanilla Debian Sarge) is similar to
that of RedHat (each user has, by default, his own group). So
my .mozilla files are owned by user.user (where 'user' is the actual
username which I use for browsing).
Maybe you could modify files because the other user, which you used,
belonged to the same group?
--- Omer
--
MS-Windows is the Pal-Kal of the PC world.
My own blog is at http://tddpirate.livejournal.com/
My opinions, as expressed in this E-mail message, are mine alone.
They do not represent the official policy of any organization with which
I may be affiliated in any way.
WARNING TO SPAMMERS: at http://www.zak.co.il/spamwarning.html
=================================================================
To unsubscribe, send mail to [EMAIL PROTECTED] with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail [EMAIL PROTECTED]