Path: utzoo!mnetor!tmsoft!torsqnt!news-server.csri.toronto.edu!bonnie.concordia.ca!uunet!fub!tmpmbx!scuzzy!src From: src@scuzzy.in-berlin.de (Heiko Blume) Newsgroups: comp.unix.sysv386 Subject: Re: SECURITY BUG IN INTERACTIVE UNIX SYSV386 Keywords: BAD BUG Message-ID: <1991Feb17.175001.15759@scuzzy.in-berlin.de> Date: 17 Feb 91 17:50:01 GMT References: <483@stephsf.stephsf.com> <1991Feb13.221259.1462@scuzzy.in-berlin.de> <1991Feb14.201602.21248@kith Organization: Contributed Software Lines: 19 src@scuzzy.in-berlin.de (Heiko Blume) writes: >sef@kithrup.COM (Sean Eric Fagan) writes: >>In article <1991Feb13.221259.1462@scuzzy.in-berlin.de> i made a typo: >>>not exactly, for public access to my source archive i've set up >>>a chroot() user that can't write anywhere, unhackable :-) > ^^^^^^^^^^^^^^^^^^^^^^^^^^^^ >>Sorry, that's not the case. Once you've got root access, .... >once you've got root access, yes, but you can get root access. ^^^ i wanted to write "CAN'T", of course... -- Heiko Blume <-+-> src@scuzzy.in-berlin.de <-+-> (+49 30) 691 88 93 public source archive [HST V.42bis]: scuzzy Any ACU,f 38400 6919520 gin:--gin: nuucp sword: nuucp uucp scuzzy!/src/README /your/home