Question about uid check in csh's source command

David Herron, NPR Lover david at ukma.UUCP
Wed Jan 1 05:27:57 AEST 1986


In article <2098 at phri.UUCP> roy at phri.UUCP (Roy Smith) writes:
>
>I guess I should just be able to add another call to srccat to read in
>/usr/lib/csh.login or something like that.  Reading a bit further into the
>code you find out that srccat won't source a file unless it has the same
>uid or gid as you do.  This I don't understand; why should it care?

Roy,

  It would be a security hole to have a persons .login owned by another
user id.  (This other user would always be able to have access to that
one user id).

-- 
David Herron,  cbosgd!ukma!david, david at UKMA.BITNET.

Experience is something you don't get until just after you need it.



More information about the Comp.unix.wizards mailing list