Bugtraq mailing list archives

Re: sendmail exploit script - resend


From: smb () research att com (smb () research att com)
Date: Mon, 28 Mar 94 14:51:37 EST


Does anyone know quite what the logic behind these shell checks are? They're
just a pain and a stumbling block that are trivial to work around. Is it only
Sun derived things that do this?

The ``feature'' was installed because of setuid programs that unwisely
let the shell do things, i.e., uucp.  The rationale was to protect such
programs by having the shell revert to the user's uid.

No, I don't agree, and I didn't agree then.  But Korn got a lot of
pressure from others.



Current thread: