Subject: Re: ftp(1) security hole, and suggested fixes
To: David Holland <dholland@eecs.harvard.edu>
From: David Holland <dholland@eecs.harvard.edu>
List: tech-security
Date: 08/17/1997 14:57:57
> Additionally, everything that mget generates should have ".." path
> elements filtered out.
This is, of course, not adequate, as doing "mget x*" from ~ would
still be able to write .rhosts.
I'll shut up now.
--
- David A. Holland | VINO project home page:
dholland@eecs.harvard.edu | http://www.eecs.harvard.edu/vino