nilsteampassnet / teampass_doc

8 stars 31 forks source link

Insecure permissions in linux install instructions #7

Open julia-bs opened 6 years ago

julia-bs commented 6 years ago

The linux install instructions say to set mode 0777 to a large swath of the team pass install directory. The use of 0777 means a compromise of any user level account on this machine gives access to the web side of teampass that allows for man in the middle attacks, as well as just being plain Bad Practice™.