From nobody Thu Sep 14 01:11:46 2023 X-Original-To: ports-bugs@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RmK6B6pxNz4sh5f for ; Thu, 14 Sep 2023 01:11:46 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RmK6B5lDzz3JyP for ; Thu, 14 Sep 2023 01:11:46 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1694653906; a=rsa-sha256; cv=none; b=Bzfi2O+h2uKhQFUZP7NO3KIOtiWh34kNMSsCYDcum5pGjhd+9UT/M1YugBUKKtDFT/v2DX b2WnX324R9SMv+tgQuaLuyaJwymu0APjhNptYW2Jff7Gj1Kk1nMSE3ijtxniaMFkxRg18O f753FIVfxUjJQ7XQq4iF3DOyT7EyykcXpOPi8O7Upx6P78BPJy98JeCONDR0ugaScIrYTf Ogh9S/tFEdZ1vBMVN3191/GI3sN6sGu5eEN2AyQ8OlEBQzhHpq5Rq2w5OnRzOVPaWu8bZ0 LPGslRnWUJPs4WDapa4mEk7X6IzOp37N+rPbFGqLRRv2Ta6M3q41fCxj9I7Zww== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1694653906; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XUwfyiJpXeI6XDSWKo4rvFHBOI9oT9dWP4YRgzzvGWQ=; b=FiWkv3dZcrG2w1yZJyhagrmK6KmXQyXv6P0HIFpCixRfgN9pJS/PxOcDo2lb9U5Pet+KNN KRZVFFbp5EQbEtL5Fu3vce7u4kkSPlp51KIKzayae8eIk4Jdi/slqNyG94Lx7T3ar26HXW V9DNbOD/guhd4ystbG048OQBn79aq4pyan+sWNN2YN3OjAml2wK91rZur5Y4u7EQqi6B8q NmNFaGiJk/QfCYwdlZfUUKv38us52ZaEzVUzraFX+Ie1aAFzKyCQTAKZsbYc0dFTHQy4n0 Oyv/o6QXpC6GmKR+zYaqVFDU/8ov7IGHsEMSzo1GUVQzf7N+Eu7m3zAJFXtyxw== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RmK6B4pWbzcYm for ; Thu, 14 Sep 2023 01:11:46 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 38E1BkCm007524 for ; Thu, 14 Sep 2023 01:11:46 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 38E1Bkam007523 for ports-bugs@FreeBSD.org; Thu, 14 Sep 2023 01:11:46 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: ports-bugs@FreeBSD.org Subject: [Bug 272777] [NEW PORT] www/dasherr: Lightweight dashboard for self-hosted services (and bookmarks) Date: Thu, 14 Sep 2023 01:11:46 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Ports & Packages X-Bugzilla-Component: Individual Port(s) X-Bugzilla-Version: Latest X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: fuz@FreeBSD.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: ports-bugs@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Ports bug reports List-Archive: https://lists.freebsd.org/archives/freebsd-ports-bugs List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-ports-bugs@freebsd.org X-BeenThere: freebsd-ports-bugs@freebsd.org MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D272777 --- Comment #4 from Robert Clausecker --- Thank you for informing me that other ports suffer from the same mistake. The problem is as follows: files owned by www are writable by the http daem= on (whichever it is). So if there is a bug in the web application, an attacker can very likely use it to modify the web application itself, persisting the attack and possibly establishing a remote shell. Thus, files that don't ne= ed to be writable by httpd must not be owned by www! Only give files to www t= hat httpd needs to write. Ports that do this wrong have a possible security is= sue and should be fixed. > Of course, I listen to any other recommendations, but I think www is fine. No, it is not fine. Please also fix your other ports if they make the same mistake. --=20 You are receiving this mail because: You are the assignee for the bug.=