aaarrgh! (was: Re: setuid shell scripts)

Maarten Litmaath maart at cs.vu.nl
Thu Oct 26 07:20:25 AEST 1989


I wrote:
\..., put the following
\in a file /etc/fubar:
\
\	#!/bin/sh /etc/fubar
\	echo "Am I right or am I right?"

This can be cracked, of course; serves me right to post an article after an
allnighter...
Allright, how about this:

	#!/bin/sh /etc/fubar

Yeah, that's all!
Or:
	#!/bin/echo
-- 
A symbolic link is a POINTER to a file, | Maarten Litmaath @ VU Amsterdam:
 a hard link is the file system's GOTO. | maart at cs.vu.nl, mcsun!botter!maart



More information about the Comp.unix.questions mailing list