Are suid shell scripts using /bin/csh secure

Maarten Litmaath mcvax!cs.vu.nl!maart at uunet.uu.net
Tue Apr 25 15:48:12 AEST 1989


auspex!guy at uunet.uu.net (Guy Harris) writes:
\There is another hole in the "#!" mechanism that there is no way to patch
\merely by properly constructing the script.

My `/bin/setuid' approach does close that hole too; it's provably safe,
thank you. And easy. Email or check comp.sources.misc.  BTW, the `hole'
isn't a secret anymore.

 Modeless editors and strong typing:   |Maarten Litmaath @ VU Amsterdam:
   both for people with weak memories. |maart at cs.vu.nl, mcvax!botter!maart



More information about the Comp.sys.sun mailing list