Subject: Re: ftp(1) security hole, and suggested fixes
To: David Holland <dholland@eecs.harvard.edu>
From: David Holland <dholland@eecs.harvard.edu>
List: tech-security
Date: 08/17/1997 14:57:57
 > Additionally, everything that mget generates should have ".." path
 > elements filtered out. 

This is, of course, not adequate, as doing "mget x*" from ~ would
still be able to write .rhosts.

I'll shut up now.

-- 
   - David A. Holland             |    VINO project home page:
     dholland@eecs.harvard.edu    | http://www.eecs.harvard.edu/vino