World Book

By: Scott Doenges - Revised: 2006-05-31 devin

World Book Iconhttp://www.worldbook.com

World Book has the following insecure world write permissions:

./Library/Application Support/.smkwbwba2006 0777 501 80
./Library/Application Support/2006 World Book 0777 501 80
./Library/Application Support/2006 World Book/Download 0777 501 80
./Library/Application Support/2006 World Book/Download/mb200509.001 0777 501 80
./Library/Application Support/2006 World Book/Download/mb200510.001 0777 501 80
./Library/Application Support/2006 World Book/Download/mb200511.001 0777 501 80
./Library/Application Support/2006 World Book/Download/mb200512.001 0777 501 80
./Library/Application Support/2006 World Book/Download/mb200601.001 0777 501 80
./Library/Application Support/2006 World Book/Download/mb200602.001 0777 501 80
./Library/Application Support/2006 World Book/Download/mb200603.001 0777 501 80
./Library/Application Support/2006 World Book/Download/online.upd 0777 501 80
./Library/Application Support/2006 World Book/Download/pc322480.gif 0777 501 80
./Library/Application Support/2006 World Book/Download/pc322500.gif 0777 501 80
./Library/Application Support/2006 World Book/Download/pc322826.gif 0777 501 80
./Library/Application Support/2006 World Book/Download/pc322950.gif 0777 501 80
./Library/Application Support/2006 World Book/Download/pc323033.gif 0777 501 80
./Library/Application Support/2006 World Book/Download/pc323488.gif 0777 501 80
./Library/Application Support/2006 World Book/Download/pc323695.gif 0777 501 80
./Library/Application Support/2006 World Book/Download/up200511.016 0777 501 80
./Library/Application Support/2006 World Book/Download/up200512.016 0777 501 80
./Library/Application Support/2006 World Book/Download/up200601.016 0777 501 80
./Library/Application Support/2006 World Book/Download/up200602.006 0777 501 80
./Library/Application Support/2006 World Book/Download/wu200602.001 0777 501 80
./Library/Application Support/2006 World Book/WebSites.tdb 0777 501 80

However, if you modify these privileges the following error results when you attempt to update:

World Book Error

To fix this you need to create a simlink that will store the files with full permissions in the user's library instead of the world library, eliminating the security risk:

"ln -s /Library/Application Support/2006 World Book/ /Users/Authenticated User/Library/Application Support/2006 World Book/"