Skip to main content

Question about world writable files

1 reply [Last post]
Joined: 2004-05-19

I don't know a lot about Java but was required to run a security test on a solaris machine with jre installed on it. Some of the files were found to be world writable (against one of the security polices). an example file is /jre/lib/sparc/native_threads/
The owner of this file is the web server. Would a webserver need to change/write to this type of file? What exactly is a .so file? Is it possible this file doesn't need to be worldwritable?

Reply viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Joined: 2003-06-13

a .so is a library, like dlls and it should never ever ever be world-writable.

Please re-install the package that owns this file since this contains executable code.