home *** CD-ROM | disk | FTP | other *** search
- Submitted-by: gwc@root.co.uk (Geoff Clare)
-
- peter@ficc.ferranti.com (Peter da Silva) writes:
-
- >In article <1991Jul12.213625.7241@uunet.uu.net> decot@hpcupt1.cup.hp.com (Dave Decot) writes:
- >> To be sure that you are "securely" running a standard utility, POSIX.2
- >> provides the standard utility path via "getconf CS_PATH" that applications
- >> can change their PATH to, and be assured of getting the standard version.
-
- >Is getconf a builtin? If not, it itself can be spoofed!
-
- Even if getconf is a builtin in the POSIX shell, what is there to stop
- users running these "secure" scripts under a non-standard shell with a
- getconf that just echoes the current PATH?
-
- [ Requiring shell scripts to be interpreted by a specific shell or by
- a shell specified by the script, I would imagine. -- mod ]
-
- --
- Geoff Clare <gwc@root.co.uk> (USA UUCP-only mailers: ...!uunet!root.co.uk!gwc)
- UniSoft Limited, London, England. Tel: +44 71 729 3773 Fax: +44 71 729 3273
-
- Volume-Number: Volume 24, Number 54
-
-