home *** CD-ROM | disk | FTP | other *** search
- On Wed, 29 Dec 1993, David Jones wrote:
- > The solution was to make XTerm setuid root.
- A quick note from the Security Guy at Oregon State University... :^)
-
- I'm not sure that this is a good place to mention this, but if you're
- putting your machine on the net, you should know that there is a huge
- security hole in most versions of XTerm. Basically, making it suid root
- allows you to use the logging options to do nasty things. I very much
- recommend that you recompile XTerm *without* the logging function. This
- alleviates the problem. Please feel free to mail me personally if you
- have questions about this...
-
- -rAT (He of the SubHuman Strength :^)
-
- O----O email : rat@cs.orst.edu : CS Isupport
- \oo/ __ "This is the most fun I've ever had with someone else's clothes!"
- ==\/== \/ - Kathy Lowe
-
-
-