Path: utzoo!utgpu!news-server.csri.toronto.edu!cs.utexas.edu!sol.acs.unt.edu!mstgil From: mstgil@sol.acs.unt.edu (Marc Ph. A. J. St.-Gil) Newsgroups: comp.unix.admin Subject: Re: Mysterious security hole Message-ID: <1991Jun12.184051.853@sol.acs.unt.edu> Date: 12 Jun 91 18:40:51 GMT References: <91161.131540SCHDAVZ@YaleVM.YCC.Yale.Edu> Reply-To: mstgil@sol.acs.unt.edu Organization: University of North Texas Lines: 13 cgd@ocf.Berkeley.EDU (Chris G. Demetriou) writes: >In article <91161.131540SCHDAVZ@YaleVM.YCC.Yale.Edu> SCHDAVZ@YaleVM.YCC.Yale.Edu (Dave Schweisguth) writes: >> >Say, for example, that PATH is set so that . comes before /bin - >Also, say that someone has in a directory a shell script, executable, or >whatever named the same as a common command in /bin such as, say, rm. How about 'ls' instead of 'rm'... much easier to see the danger here what's the most common command you use after changing to a new directory? ^^^^^^^^^^ a rhetorical question :) --