5 ms·
I do not understand why symbolic links are "poisonous"? Can I get some context?
by sippycup6 4y ago
I do not understand why symbolic links are "poisonous"? Can I get some context?
- Thorrez 4y agoI think it's just that they're tricky when it comes to ownership. People who write code that depends on some type of file or directory ownership for security often don't think about the ways symlinks can be used to bypass their security model. You can sort of think of a symlink as having 2 owners: the user that owns the symlink itself, and the user who owns the file pointed to by the symlink. One of those owners might be an attacker, so every time you interact with a file, you have to think "this file might be half-owned by an attacker, and half-owned by a victim".
- sippycup6 4y agoThank you!
- mishafb 4y agoDaemons that care about security setuid temporarily before opening a file and then setuid back
- jra_samba 4y agoThat doesn't always fix it. An attacker can race you to make you write something in a place you didn't intend or expect unless the application is incredibly carefully written. And by "incredibly" I mean beyond the scope of human endeavour :-).
- jra_samba 4y agoI'm going to be giving a talk at SambaXP this year (it's virtual, so you only need to register to attend) explaining why IMHO symlinks have utterly broken the POSIX filesystem API, making it impossible for application developers to write secure applications. https://sambaxp.org/ https://sambaxp.org/ It's not just a whine, I'm also going to make some suggestions for fixing it :-).