It is currently Fri May 24, 2013 11:43 pm

All times are UTC - 6 hours [ DST ]




Post new topic Reply to topic  [ 4 posts ] 
Author Message
 Post subject: root
PostPosted: Sun Oct 03, 2010 3:38 pm 
Rookie Tonidoid
Rookie Tonidoid
Joined: Sun Oct 03, 2010 3:26 pm
Posts: 8

Each file uploaded using webshare is stored in my filesystem with owner and group "root". I guess it is a strong security risk.

If a wrong setup is causing this, please let me know correct configuration, or a tutorial with tonido security guidelines.


Offline
 Profile  
 Post subject: Re: root
PostPosted: Sun Oct 03, 2010 4:25 pm 
Admin Tonidoid
Admin Tonidoid
User avatar
Joined: Tue Dec 30, 2008 12:13 am
Posts: 7311
Location: Dallas, USA

Is this on the tonidoplug?
On the TonidoPlug, the tonido process runs as root so the files are created as root.


Offline
 Profile  
 Post subject: Re: root
PostPosted: Sat Oct 16, 2010 3:27 pm 
Rookie Tonidoid
Rookie Tonidoid
Joined: Sun Oct 03, 2010 3:26 pm
Posts: 8

Yes, this is on the tonidoplug.

Running processes as root and creating files as root may expose a big security risk.

What's Codelathe point of view / security recommendations about this?


Offline
 Profile  
 Post subject: Re: root
PostPosted: Sat Oct 16, 2010 4:11 pm 
Admin Tonidoid
Admin Tonidoid
User avatar
Joined: Tue Dec 30, 2008 12:13 am
Posts: 7311
Location: Dallas, USA

TonidoPlug is a single function embedded device instead of a general purpose computer.
We agree that in general running as root is not ideal, but to accomplish the functionality that TonidoPlug has, it required root privileges.


Offline
 Profile  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC - 6 hours [ DST ]


 Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to: