disallowing subshell in More
mikeh at haddock.UUCP
mikeh at haddock.UUCP
Mon Feb 11 15:37:38 AEST 1985
Hi there,
Just a thought, more(1) uses the enviornment variable $SHELL to
determine what shell to invoke. The root id caller of more sets
SHELL to an innocuous program the hole vanishes. I would
overimplement and have the $SHELL program setuid and setgid to
the user and then exec the users faviorite shell, but setting
$SHELL to /bin/true would probably work. Not, what holes are in
my scheme?
mike &
Herbie
More information about the Comp.unix.wizards
mailing list