diff options
author | lukem <lukem@NetBSD.org> | 1998-06-08 12:41:41 +0000 |
---|---|---|
committer | lukem <lukem@NetBSD.org> | 1998-06-08 12:41:41 +0000 |
commit | 1ee27fa489453810240f86207f73bfe80568dfcc (patch) | |
tree | 3736dbb72cf9ee555fc8786832768fa341801ab5 /dm/dm.8 | |
parent | 66b9cf2df4cb403bc5837c004df443dba33527d8 (diff) | |
download | bsdgames-darwin-1ee27fa489453810240f86207f73bfe80568dfcc.tar.gz bsdgames-darwin-1ee27fa489453810240f86207f73bfe80568dfcc.tar.zst bsdgames-darwin-1ee27fa489453810240f86207f73bfe80568dfcc.zip |
Implement a new manual page category ``SECURITY CONSIDERATIONS''
(suggested by mycroft)
Diffstat (limited to 'dm/dm.8')
-rw-r--r-- | dm/dm.8 | 32 |
1 files changed, 16 insertions, 16 deletions
@@ -1,4 +1,4 @@ -.\" $NetBSD: dm.8,v 1.5 1998/04/28 06:00:52 fair Exp $ +.\" $NetBSD: dm.8,v 1.6 1998/06/08 12:41:41 lukem Exp $ .\" .\" Copyright (c) 1987, 1991, 1993 .\" The Regents of the University of California. All rights reserved. @@ -86,26 +86,26 @@ game logging file .El .Sh SEE ALSO .Xr dm.conf 5 -.Sh BUGS -Two problems result from +.Sh HISTORY +The +.Nm +command appeared in +.Bx 4.3 tahoe . +.Sh SECURITY CONSIDERATIONS +Two issues result from .Nm -running the games setuid +running the games setgid .Dq games . First, all games that allow users to run .Ux commands should carefully -set both the real and effective user id's immediately before executing -those commands. Probably more important is that +set both the real and effective group id's immediately before executing +those commands. +Probably more important is that .Nm -never be setuid -anything but +never be setgid anything but .Dq games so that compromising a game will result only in -the user's ability to play games at will. Secondly, games which previously -had no reason to run setuid and which accessed user files may have to -be modified. -.Sh HISTORY -The -.Nm -command appeared in -.Bx 4.3 tahoe . +the user's ability to play games at will. +Secondly, games which previously had no reason to run setgid and which +accessed user files may have to be modified. |