Bugtraq mailing list archives
Re: PATH variable in zip-slackware 2.0.35
From: rattle () TLORAH NET (Rattle)
Date: Mon, 4 Jan 1999 02:29:24 -0600
On Sat, 21 Nov 1998, Cacaio Torquato wrote:
Just FYI: As I have seen in Slackware 3.4 CD-Rom, these two entries are also in the default PATH. Maybe this entrie is also included in the default PATH of other versions of Slackware.
As far as I can remember, "/usr/andrew" and "." have been in the PATH on every version of Slackware I have ever installed. Which probably meants its even in pre 2.0 releases. While the presence "/usr/andrew" is (in most cases) nothing more than "clutter", having "." is your path is a very common mistake admins make. Mainly because people can be to lazy to type ./configure when installing packages. As previously mentioned, this can is used by the common script kiddie to easily make a suid shell or other 4xxx toy for himself. Many a machine has been cracked by someone inserting a script named "ls" in the /tmp dir. Also, there are hooks in various Slackware startup scripts (ie: /etc/rc.d/rc.inet2) to startup various daemons that are not installed by default. The first one that comes to mind is sshd. While this is not a security risk (as it only looks to the dirs "/usr/sbin" and "/usr/local/sbin"). I may be mistaken (Its kinda late here.. heh), but I can sware that it is not commented out by default. As I said, not a blatent security risk, but if you have sshd installed, but don't want it to run.. You may want to comment that out. (And if you don't use ssh/scp, you should..) ... . Nick Levay . rattle () tlorah net . "There are two major products that come out of Berkeley: LSD and UNIX. . We do not believe this to be a coincidence."
Current thread:
- Re: Comparison of THC-SCAN v2.0 with Sandstorm PhoneSweep 1.02 Adam Maloney (Dec 31)
- ACC's 'Tigris' Access Terminal server security vunerability.. Robert Thomas (Jan 02)
- Re: ACC's 'Tigris' Access Terminal server security vunerability.. Patrik Backstrom (Jan 03)
- Re: Comparison of THC-SCAN v2.0 with Sandstorm PhoneSweep 1.02 Oliver Xymoron (Jan 02)
- PATH variable in zip-slackware 2.0.35 Steven Alexander (Jan 02)
- Re: PATH variable in zip-slackware 2.0.35 Cacaio Torquato (Nov 20)
- Re: PATH variable in zip-slackware 2.0.35 Rattle (Jan 04)
- Re: PATH variable in zip-slackware 2.0.35 Patrick J. Volkerding (Jan 04)
- Re: PATH variable in zip-slackware 2.0.35 bandregg () REDHAT COM (Jan 05)
- Re: PATH variable in zip-slackware 2.0.35 Cacaio Torquato (Nov 20)
- Re: PATH variable in zip-slackware 2.0.35 Karl Stevens (Jan 04)
- Re: PATH variable in zip-slackware 2.0.35 kay (Jan 02)
- Re: PATH variable in zip-slackware 2.0.35 Karl Stevens (Jan 05)
- Re: PATH variable in zip-slackware 2.0.35 kay (Jan 06)
- ACC's 'Tigris' Access Terminal server security vunerability.. Robert Thomas (Jan 02)
- l0phtcrack 2.5 released The Forlorn (Jan 04)
- Re: SUN almost has a clue! (automountd) Casper Dik (Jan 05)