Re: jserver socket permissions

On Mon, 13 Jan 1997, Craig Oda wrote:

craig>Jserver then automatically creates a socket in /tmp.
craig>srwxr-xr-x   1 root     root            0 Jan 13 22:32 jd_sockV4=
craig>As can be seen from the permissions above, only root can write
craig>to the socket.  I can solve this by changing the permissions
craig>to 1777.  However, I was wondering if this was a security problem
craig>or not.  I guess I can simply add the lines

Yes it could be a security problem, depending on what the uid of the
jserver process is.

craig>if [ -f /tmp/jd_sockV4 ]; then
craig>	chmod 1777 /tmp/jd_sockV4
craig>to the  rc.local file...  Any ideas?
craig>I'm planning If the permissions are automatically set to 1755, it
craig>must be a problem for other people too, right?

What port are you running the jserver on ?.  Is it running as root or as a
specific uid ?.  


