[6255] in RedHat Linux List
Re: More redhat-4.0 security
daemon@ATHENA.MIT.EDU (Steve \"Stevers!\" Coile)
Tue Nov 26 14:28:24 1996
Date: Tue, 26 Nov 1996 14:00:22 -0500 (EST)
From: "Steve \"Stevers!\" Coile" <scoile@patriot.net>
To: Chris Evans <chris@ferret.lmh.ox.ac.uk>
cc: redhat-list@redhat.com
In-Reply-To: <Pine.LNX.3.95.961126175042.29473A-100000@ferret.lmh.ox.ac.uk>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
On Tue, 26 Nov 1996, Chris Evans wrote:
> Hi, a minor point this time (in my "RedHat security drive"), but
> /usr/local/bin appears before /bin,/usr/bin, etc. in my path.
>
> Whereas I certainly don't, some sites allow people to install their own
> binaries/other stuff under /usr/local. This might open up trojan
> possibilities.
I have *never* heard of a site giving unprivileged users write access
to /usr/local/bin. I'd be extremely surprised to find such a site.
/usr/local/bin occurs before /bin and /usr/bin to allow the *system
management* (the only ones that *should* have access to /usr/local/bin,
IMHO) to override the behavior of standard commands (e.g. installing a
color-ls as /usr/local/bin/ls to override /bin/ls).
--
Steve Coile P a t r i o t N e t Systems Engineering
scoile@patriot.net Patriot Computer Group (703) 277-7737
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null