Hacker News new | past | comments | ask | show | jobs | submit login

It's a kind of attack called a symlink race, which is also possible on other operating systems. There are kernel parameters for hardening against symlink races on Linux, and they just disable symlinking into world-writable locations. I'm not sure why Windows can't use a less invasive mitigation like that, but I guess there must be one.



A lot more tends to be world-writable in Windows, for starters.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: