tech-userlevel archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Moving rc.d scripts to base.tgz

On Thu, Apr 14, 2011 at 06:54:14PM -0400, Thor Lancelot Simon wrote:

> If I'm concerned about the possibility of configuring a system daemon
> in such a dangerous way, I can remove it -- or elsewise pin down its
> configuration.

Like the system daemon /bin/sh or is just inetd evil ?
What about ttys ? gettytab ? profile ? crontab ? ifconfig.IF ? cgd.conf ?

Almost every file in /etc can be used to compromise your system
and many files provide hooks that cause something to run and execute
at startup.

                                Michael van Elst
                                "A potential Snark may lurk in every tree."

Home | Main Index | Thread Index | Old Index