Subject: Re: tar ignores filenames that contain `..' To: David Laight <email@example.com> From: Perry E. Metzger <firstname.lastname@example.org> List: tech-security Date: 10/31/2002 12:01:20
David Laight <email@example.com> writes:
> > can't chroot as a normal user?
> A normal user can't overwrite anything (very) improtant.
Untrue. Many break-ins succeed by getting normal users to do things...