in reply to Re^4: On being 'critical'
in thread On being 'critical'
As you point out, if real and effective user ids are different, taint mode is enabled automatically. So even if a script relying upon <> is accidently given the setuid bit, nothing nasty happens. That means the attack is not an attack.
My question still stands.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Two-argument open, and reading already open files.
by pjf (Curate) on Dec 17, 2006 at 06:55 UTC | |
|
Re^6: On being 'critical'
by Sartak (Hermit) on Dec 15, 2006 at 07:22 UTC | |
by BrowserUk (Patriarch) on Dec 15, 2006 at 07:58 UTC | |
by sauoq (Abbot) on Dec 15, 2006 at 20:29 UTC | |
by Sartak (Hermit) on Dec 15, 2006 at 08:30 UTC | |
by BrowserUk (Patriarch) on Dec 15, 2006 at 09:20 UTC |