Subject: Re: bin/4489: /usr/games/fish allows setuid games binaries to be created by unprivileged user
To: Mike Long <mikel@shore.net>
From: Jon Ribbens <jon@oaktree.co.uk>
List: tech-security
Date: 11/18/1997 19:08:46
Mike Long <mikel@shore.net> wrote:
> >This isn't just an esoteric problem. I wonder how many people have
> >'fortune' in their /etc/profile? Wouldn't take you long to get a root shell.
> 
> This is a bit of a red herring; fortune(6) isn't controlled by dm.

Oh, um, you're right. I was sure I'd checked that ;-) :(.

Cheers


Jon
____
\  //    Jon Ribbens    // 100MB virtual-hosted // www.oaktree.co.uk
 \// jon@oaktree.co.uk //  web space for 99UKP //