[14745] in bugtraq

home help back first fref pref prev next nref lref last post

Re: aaa_base still vulnerable after upgrade

daemon@ATHENA.MIT.EDU (Horst von Brand)
Tue May 2 17:15:36 2000

Message-Id:  <200005011457.e41Evma02055@sleipnir.valparaiso.cl>
Date:         Mon, 1 May 2000 10:57:48 -0400
Reply-To: Horst von Brand <vonbrand@SLEIPNIR.VALPARAISO.CL>
From: Horst von Brand <vonbrand@SLEIPNIR.VALPARAISO.CL>
X-To:         Marc Heuse <marc@SUSE.DE>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  Message from Marc Heuse <marc@SUSE.DE> of "Sat, 29 Apr 2000
              19:01:20 +0200." <20000429170120.70A6F67AD@Galois.suse.de>

Marc Heuse <marc@SUSE.DE> said:

[...]

> > touch "/tmp/x /etc/rc.config"

> btw have you ever tried out this command? It won't work. A filename is not
> allowed to have a slash in it's name ...

True. But spaces are legal... this is file etc/rc.config inside directory
"x " inside /tmp

Note that Red Hat duistributes a binary called tmpwatch (written by them
and GPL) which safely deletes /tmp entries. Quite old, AFAIKT.
--
Horst von Brand                             vonbrand@sleipnir.valparaiso.cl
Casilla 9G, Viqa del Mar, Chile                               +56 32 672616

home help back first fref pref prev next nref lref last post