Unix Technical Forum

Re: small patch to etc/skel/dot.cshrc

This is a discussion on Re: small patch to etc/skel/dot.cshrc within the mailing.openbsd.tech forums, part of the OpenBSD category; --> what now ? openbsd has to be responsible for the typos the user makes ? -p. On Wed, Feb ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 06:48 AM
Pedro Martelletto
 
Posts: n/a
Default Re: small patch to etc/skel/dot.cshrc

what now ? openbsd has to be responsible for the typos the user makes ?

-p.

On Wed, Feb 18, 2004 at 01:54:38AM +0100, Marc Bevand wrote:
> I also think '.' should be remove from the PATH. Example:
> - imagine an evil hacker places a binary (trojan...) called 'sl'
> in /tmp
> - if '.' is in the default PATH, the hacker would just have
> to wait long enough so that a user (whose cwd happens to be
> /tmp) mistypes 'sl' (instead of 'ls') so that it executes the
> trojan
> This simple attack is really used by the bad guys and works very well
> on massively multiuser systems.
>
> --
> Marc Bevand http://www.epita.fr/~bevand_m
> Computer Science School EPITA - System, Network and Security Dept.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 01:43 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com