From owner-freebsd-bugs Wed Oct 23 13:54:11 1996 Return-Path: owner-bugs Received: (from root@localhost) by freefall.freebsd.org (8.7.5/8.7.3) id NAA10555 for bugs-outgoing; Wed, 23 Oct 1996 13:54:11 -0700 (PDT) Received: from irz301.inf.tu-dresden.de (irz301.inf.tu-dresden.de [141.76.1.11]) by freefall.freebsd.org (8.7.5/8.7.3) with SMTP id NAA10513 for ; Wed, 23 Oct 1996 13:53:03 -0700 (PDT) Received: from sax.sax.de (sax.sax.de [193.175.26.33]) by irz301.inf.tu-dresden.de (8.6.12/8.6.12-s1) with ESMTP id WAA26838; Wed, 23 Oct 1996 22:52:09 +0200 Received: (from uucp@localhost) by sax.sax.de (8.6.12/8.6.12-s1) with UUCP id WAA01612; Wed, 23 Oct 1996 22:52:08 +0200 Received: (from j@localhost) by uriah.heep.sax.de (8.7.6/8.6.9) id WAA27794; Wed, 23 Oct 1996 22:49:20 +0200 (MET DST) From: J Wunsch Message-Id: <199610232049.WAA27794@uriah.heep.sax.de> Subject: Re: docs/1383 To: marcs@worldgate.com (Marc Slemko) Date: Wed, 23 Oct 1996 22:49:20 +0200 (MET DST) Cc: freebsd-bugs@FreeBSD.org (FreeBSD bugs list) Reply-To: joerg_wunsch@uriah.heep.sax.de (Joerg Wunsch) In-Reply-To: from Marc Slemko at "Oct 23, 96 08:18:28 am" X-Phone: +49-351-2012 669 X-PGP-Fingerprint: DC 47 E6 E4 FF A6 E9 8F 93 21 E0 7D F9 12 D6 4E X-Mailer: ELM [version 2.4ME+ PL17 (25)] MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: owner-bugs@FreeBSD.org X-Loop: FreeBSD.org Precedence: bulk As Marc Slemko wrote: > > There are not much risks with `interpreted executables' other than > > the one described there. This one however can easily be avoided by > > suggesting > > > > #!/bin/sh > > exec /usr/sbin/ppp -direct > > > > in the man page. > > Not true. Doing so will NOT avoid the problem. Ahhhrg. I should have read the entire audit-trail before. Now i see that i've already looked at it earlier... The shell should really have the equivalent of csh -f. (sh -q? Any opinions on this?) The only alternative by now to your attack is putting a ``kill 0'' on top of /etc/shells. ;-) -- cheers, J"org joerg_wunsch@uriah.heep.sax.de -- http://www.sax.de/~joerg/ -- NIC: JW11-RIPE Never trust an operating system you don't have sources for. ;-)