Complications when auditing Unix system security
September 7th, 2008 | by admin |When performing a unix security audit, a user can specify target (uid or gid) on the command line, and a user can use -f to preload file owner, group and mode info, which is helpful in terms of speed and avoiding file system ’shadows’. Users that are not satisfied with the crippled shell can’t replace it, since the replacement cannot have the required trust. This is found to be an unacceptable violation of the concept that the entire user-level environment be replaceable on a per-user basis.










