disallowing subshell in More

mikeh at haddock.UUCP mikeh at haddock.UUCP
Mon Feb 11 15:37:38 AEST 1985


Hi there,
	Just a thought, more(1) uses the enviornment variable $SHELL to 
	determine what shell to invoke.  The root id caller of more sets 
	SHELL to an innocuous program the hole vanishes.  I would 
	overimplement and have the $SHELL program setuid and setgid to 
	the user and then exec the users faviorite shell, but setting 
	$SHELL to /bin/true would probably work.  Not, what holes are in 
	my scheme?  
								mike &
								Herbie



More information about the Comp.unix.wizards mailing list