[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Should gcc be usable by world ?



Hi:

 I see that gcc, g++, and other tools are usable by world (others). I was wondering if that is a bad idea as I read here: http://www.itworld.com/nl/lnx_sec/09242002/pf_index.html
that the slapper worm used gcc to compile it's exploit.
 Excerpt: The worm requires gcc to compile the .bugtraq.c file. .... 

Is it a good idea to change the permisions on the gcc tools to 750 ? I looked through the FreeBSD Handbook and could find no advice on this matter. Also, are there other tools that should not be available like strace? How can I find out which ones are potentially
exploitable?

                               Kind regards,
                               Jonathan    

-
To unsubscribe, send email to majordomo@silug.org with
"unsubscribe silug-discuss" in the body.