/bin/sh: the biggest Unix security loophole (1984) [pdf]
1–10 of 57 posts
Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#2Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#3When I was working for a major retailer, who, you'd assume would have thought about these things well enough, you were prevented from executing sudo, except for being able to use it for text editing (sudo vi). I needed to install some packages with a root shell at the time, so I used the command execution feature within vi to get that.
Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#4Loopholes of this kind exist these days as well. When I was working for a major retailer, who, you'd assume would have thought about these things well enough, you were prevented from executing sudo, except for being able to use it for text editing (sudo vi). I needed to install some packages with a root shell at the time, so I used the command execution feature within vi to get that.
Of course there was nothing else in the UI except this window and the browser, but on ancient Firefox, in the print window you had the option to specify the command line to print. I tried "xterm", hit "Print", and voila, a prompt!
Using ps, I managed to figure out the difference between the unpaid browser and the paid one, and next time around I could launch a browsing session without payment...
Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#5Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#6Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#7Loopholes of this kind exist these days as well. When I was working for a major retailer, who, you'd assume would have thought about these things well enough, you were prevented from executing sudo, except for being able to use it for text editing (sudo vi). I needed to install some packages with a root shell at the time, so I used the command execution feature within vi to get that.
Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#8Loopholes of this kind exist these days as well. When I was working for a major retailer, who, you'd assume would have thought about these things well enough, you were prevented from executing sudo, except for being able to use it for text editing (sudo vi). I needed to install some packages with a root shell at the time, so I used the command execution feature within vi to get that.
Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#9Loopholes of this kind exist these days as well. When I was working for a major retailer, who, you'd assume would have thought about these things well enough, you were prevented from executing sudo, except for being able to use it for text editing (sudo vi). I needed to install some packages with a root shell at the time, so I used the command execution feature within vi to get that.
Re: /bin/sh: the biggest Unix security loophole (1984) [pdf]
#10Loopholes of this kind exist these days as well. When I was working for a major retailer, who, you'd assume would have thought about these things well enough, you were prevented from executing sudo, except for being able to use it for text editing (sudo vi). I needed to install some packages with a root shell at the time, so I used the command execution feature within vi to get that.