HP3000-L Archives

March 2005, Week 2

HP3000-L@RAVEN.UTC.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Greg Stigers <[log in to unmask]>
Reply To:
Greg Stigers <[log in to unmask]>
Date:
Wed, 9 Mar 2005 18:52:27 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (11 lines)
Lars Appel wrote:
> By the way, the fully qualified "/bin/ls" inside the shell's
> -c parameter is not required, a simple "ls" is sufficient...
Sufficient, but unsafe. This is a known exploit. Without the pathing, ls
will be picked up from wherever it is first found in the path variable.

Greg Stigers

* To join/leave the list, search archives, change list settings, *
* etc., please visit http://raven.utc.edu/archives/hp3000-l.html *

ATOM RSS1 RSS2