[6255] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: More redhat-4.0 security

daemon@ATHENA.MIT.EDU (Steve \"Stevers!\" Coile)
Tue Nov 26 14:28:24 1996

Date: Tue, 26 Nov 1996 14:00:22 -0500 (EST)
From: "Steve \"Stevers!\" Coile" <scoile@patriot.net>
To: Chris Evans <chris@ferret.lmh.ox.ac.uk>
cc: redhat-list@redhat.com
In-Reply-To: <Pine.LNX.3.95.961126175042.29473A-100000@ferret.lmh.ox.ac.uk>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com

On Tue, 26 Nov 1996, Chris Evans wrote:
> Hi, a minor point this time (in my "RedHat security drive"), but
> /usr/local/bin appears before /bin,/usr/bin, etc. in my path.
> 
> Whereas I certainly don't, some sites allow people to install their own
> binaries/other stuff under /usr/local. This might open up trojan
> possibilities.

I have *never* heard of a site giving unprivileged users write access
to /usr/local/bin.  I'd be extremely surprised to find such a site.

/usr/local/bin occurs before /bin and /usr/bin to allow the *system
management* (the only ones that *should* have access to /usr/local/bin,
IMHO) to override the behavior of standard commands (e.g. installing a
color-ls as /usr/local/bin/ls to override /bin/ls).

--
    Steve Coile           P a t r i o t  N e t      Systems Engineering
 scoile@patriot.net      Patriot Computer Group        (703) 277-7737


--
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
  ________________________________________________________________________
  http://www.redhat.com/RedHat-FAQ   http://www.redhat.com/RedHat-Errata
  http://www.redhat.com/RedHat-Tips  http://www.redhat.com/mailing-lists
  ------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null


home help back first fref pref prev next nref lref last post