Subject: Re: ftp mget security hole
To: Luke Mewburn <lm@cs.rmit.edu.au>
From: Johan Danielsson <joda@pdc.kth.se>
List: tech-security
Date: 11/07/1997 17:48:54
Luke Mewburn <lm@cs.rmit.edu.au> writes:

> It's not as easy to solve the ``leading ../'' problem in an othorgonal
> way, that won't break existing *valid* behaviour: do you have any
> suggestions on how to do this ? (Don't forget that some people like
> to do "mget */*", and have it work.

What I did was to (in non interactive mode) ignore files starting with
`../' and `/'.

/Johan