Re: mu 7 disk/mu setup/mu tech

From: Andreas Manser, (amanser@hsr.ch)
Date: Mon Sep 11 2000 - 12:12:10 CEST


Dumas Patrice wrote:

> not necessarily a good think to have . in PATHs, for security reasons, but
> in fact I don't know why.
>
>

The reason is that if you got the . in PATH some badboys might write a script,
prog
with a name like cd or ls which he would copy in some public directory of
yours.
lets say in /tmp or something similar. the prog could now first do some nasty
things
an after that it would call th normal cd. so you wouldn't even notice you got
some
kind of 'troyan'.
hope i've been correct with everything (and understandabel)
greetings

--
 _  _ ___ ___  Andreas Manser
| || / __| _ \ HSR Hochschule Rapperswil; Oberseestrasse 10;
| __ \__ \   / CH-8640 Rapperswil; Switzerland; Fax:+41 55 222 4400
|_||_|___/_|_\ EMAIL: amanser@hsr.ch; WWW:www.hsr.ch
---------------------------------------------------------------------
To unsubscribe, e-mail: mulinux-unsubscribe@sunsite.auc.dk
For additional commands, e-mail: mulinux-help@sunsite.auc.dk


This archive was generated by hypermail 2.1.6 : Sat Feb 08 2003 - 15:27:15 CET