Subject: Re: setuid ssh
To: Hubert Feyrer <hubert.feyrer@informatik.fh-regensburg.de>
From: Curt Sampson <cjs@cynic.net>
List: tech-security
Date: 10/17/2000 17:51:10
  by mail.netbsd.org with SMTP; 17 Oct 2000 21:51:12 -0000
	by platonic.cynic.net (Postfix) with ESMTP
	id DF2835D13; Tue, 17 Oct 2000 17:51:10 -0400 (EDT)
Date: Tue, 17 Oct 2000 17:51:10 -0400 (EDT)
From: Curt Sampson <cjs@cynic.net>
To: Hubert Feyrer <hubert.feyrer@informatik.fh-regensburg.de>
Cc: tech-security@netbsd.org
Subject: Re: setuid ssh
In-Reply-To: <Pine.GSO.4.21.0010172342220.29711-100000@rfhpc8320.fh-regensburg.de>
Message-ID: <Pine.LNX.4.21.0010171750130.1182-100000@fmh.fw.px.fulton.blink.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

On Tue, 17 Oct 2000, Hubert Feyrer wrote:

> which ones?

Aside from the usual dangers of buffer overflows and whatnot, it enables
rhosts. Charles can probably provide better details.

cjs
-- 
Curt Sampson  <cjs@cynic.net>  917 532 4208   de gustibus, aut bene aut nihil

She saw that he had singled her out from the three...for no reasoned purpose
of further acquaintance, but in commonplace obedience to conjunctive orders
from headquarters, unconsciously received by unfortunate men when the last
intention of their lives is to be occupied with the feminine.