man: Don't suggest making groupmems user-writeable
Suggesting mode 2770 is dangerous because it makes the binary writeable by all members of the owning group which is supposed to be normal end-users. Suggest 2710 instead as is usual for s[ug]id binaries, allowing execution but neither reading nor writing. Signed-off-by: Michael Weiser <michael.weiser@gmx.de>
This commit is contained in:
@@ -180,7 +180,7 @@
|
||||
<title>SETUP</title>
|
||||
<para>
|
||||
The <command>groupmems</command> executable should be in mode
|
||||
<literal>2770</literal> as user <emphasis>root</emphasis> and in group
|
||||
<literal>2710</literal> as user <emphasis>root</emphasis> and in group
|
||||
<emphasis>groups</emphasis>. The system administrator can add users to
|
||||
group <emphasis>groups</emphasis> to allow or disallow them using the
|
||||
<command>groupmems</command> utility to manage their own group
|
||||
@@ -189,7 +189,7 @@
|
||||
|
||||
<programlisting>
|
||||
$ groupadd -r groups
|
||||
$ chmod 2770 groupmems
|
||||
$ chmod 2710 groupmems
|
||||
$ chown root.groups groupmems
|
||||
$ groupmems -g groups -a gk4
|
||||
</programlisting>
|
||||
|
Reference in New Issue
Block a user