Re: Patch to prevent setuid bash shells

From: Ryan Veety (rootat_private)
Date: Tue Jun 02 1998 - 08:32:22 PDT

  • Next message: Aleph One: "PPTP Vulnerability"

    I am the one that wrote the patch.  I don't know why Aleph showed up as
    the sender...
    
    It is mostly intended as a trap, for those who use shrink-wrapped scripts
    and don't really understand how they work.  Of course it does not secure
    the system, but it warns the administrator if anyone attempts a setuid
    shell, and doesn't give the offender another chance by rejecting future
    logins.
    
    Ryan
    
    
    On Mon, 1 Jun 1998, Aleph One wrote:
    
    > Notice I did not write or post the patch. For some reason LISTSERV decided
    > to put me in the from header.
    >
    > Aleph One / aleph1at_private
    > http://underground.org/
    > KeyID 1024/948FD6B5
    > Fingerprint EE C9 E8 AA CB AF 09 61  8C 39 EA 47 A8 6A B8 01
    >
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:56:23 PDT