Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] Bashing away at Unix



On 2008-03-12 09:06 -0400 (Wed), Scott Robbins wrote:

> I believe there are various reasons to not include . in a path, but I've
> forgotten what they are.  :)

Little things like someone puts a program called 'ls' in his home dir
that creates an suid copy of /bin/sh owned by the user running it (thus
allowing anybody who runs that shell to become that user). After that, it
deletes itself and runs /bin/ls with its arguments.

You change to the dir, type 'ls', and see a directory listing, none the
wiser that you've just been 0wned.

cjs
-- 
Curt Sampson       <cjs@example.com>        +81 90 7737 2974   
Mobile sites and software consulting: http://www.starling-software.com


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links