login(1) replacement

Brian Katzung katzung at laidbak.UUCP
Sat Nov 12 04:29:41 AEST 1988


SECURITY HOLE:
	Putting ':' at the beginning of the path is just
	*ABSOLUTELY BEGGING* for Trojan Horses.  Always put '.'
	search at the end if you must put it in at all.

	This goes for things like exec?p() too.

Nit:	The login() routine has one formal parameter (login.c) but
	gets called with two arguments (main.c).

 -- Brian Katzung



More information about the Alt.sources mailing list