Locate revealing contents of root:wheel 700 directories

Kris Kennaway kris at obsecurity.org
Fri Sep 24 08:50:41 PDT 2004


On Sun, Apr 21, 2002 at 01:27:14PM -0400, Dan Mahoney, System Admin wrote:
> Hi, I noticed that in freeBSD 4.5, locate shows the contents of all
> folders, even in my previously root:wheel 700 directory, /mnt/var/log.

Only if you run the locate.updatedb utility as root (i.e. in a
non-default way).  locate only searches the database, it doesn't have
any extra privileges.

Kris
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 230 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-questions/attachments/20040924/e0f1e109/attachment.bin


More information about the freebsd-questions mailing list