Unix Technical Forum

Re: small patch to etc/skel/dot.cshrc

This is a discussion on Re: small patch to etc/skel/dot.cshrc within the mailing.openbsd.tech forums, part of the OpenBSD category; --> On Wed, 2004-02-18 at 16:05, Julian Leyh wrote: > On Wed, 18 Feb 2004 01:54:38 +0100 > Marc Bevand ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 07:48 AM
Will Backman
 
Posts: n/a
Default Re: small patch to etc/skel/dot.cshrc

On Wed, 2004-02-18 at 16:05, Julian Leyh wrote:
> On Wed, 18 Feb 2004 01:54:38 +0100
> Marc Bevand <bevand_m@epita.fr> wrote:
>
> > I also think '.' should be remove from the PATH. Example:
> > - imagine an evil hacker places a binary (trojan...) called 'sl'
> > in /tmp
> > - if '.' is in the default PATH, the hacker would just have
> > to wait long enough so that a user (whose cwd happens to be
> > /tmp) mistypes 'sl' (instead of 'ls') so that it executes the
> > trojan

>
> ln -s /bin/ls /bin/sl
>
> do that for the common type errors and your system is more secure
>
> cu
> JRL


I think we need to thank the person who brought this up. "Thanks for
caring, and thanks for submitting a patch, which is more than most
people do. Please continue to view the system with a critical eye."
Theo reviewed the patch, and declined. Theo seems to have good
instincts when it comes to security. Good enough.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 06:58 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com