in reply to Re^2: Filenames named "..\n" (unix)
in thread Filenames named "..\n"

Exploits often justify paranoia...

You wouldn't want your script that looks for set-UID exploits to miss one because the cracker put it in a file named "..\n".

- tye        

  • Comment on Re^3: Filenames named "..\n" (exploits)

Replies are listed 'Best First'.
Re^4: Filenames named "..\n" (exploits)
by zzspectrez (Hermit) on Aug 02, 2005 at 06:09 UTC

    true, true... In that case you want them all..

Re^4: Filenames named "..\n" (exploits)
by Anonymous Monk on Aug 02, 2005 at 08:31 UTC
    If you have a cracker that can create set-UID exploits, the fact the file name has a newline in it is the least of your worries.