Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Unix * weirdness

Re: Unix * weirdness

From: Scott Hardy <hardy_at_RAINEY.BLUENEPTUNE.COM>
Date: Sat, 1 Jan 2000 14:37:55 -0800

Yes, that is an ancient "feature" that is well known. You used to
be able to use 'touch' on most systems to make files like that, now
on many (e.g. Solaris) you need to do something like:

echo " ">>'-rf *'

  ...to make newbie-trap files.

Just another good reason to leave '.' out of your path statement.

You can find a similar "feature" in most ftp's mget, where files
named '|sh' and such will execute commands.

-- S.
Received on Jan 01 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos