Security Issue With Linux Version: Settings.dat Is World-Readable


Recommended Posts

A user reported the following problem in Issue #122, and I agree with him:

 

Hi,

is it possible to change the permission flags to readable only by the server itself?

I classify this as an security issue.

Maybe this needs to be addressed to btsync itself.

 

/var/lib/btsync# ll -ninsgesamt 952drwxr-xr-x  2 1000 1000   4096 Apr  3 22:43 ./drwxr-xr-x 73    0    0   4096 Apr  3 22:25 ../...-rw-r--r--  1 1000 1000   2919 Apr  3 21:58 settings.dat...

In my opinion there is no real workaround for this: setting an UMASK that prevents this, affects also the shared folders.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.