In article <bjl.713562403@freyr>, bjl@loki.pttrnl.nl (Ben Lippolt) writes:Although this can be done, it is generally considered a terrible security risk when done in the root account. The point is that the superuser should be running only programs which (s)he knows the location of; for example, if you have a . in your path and you execute "alias dir 'ls -lasg'" in csh, you can quite easily have just run a program in the current directory, called alias, which wipes your disk out. Obviously, you're not going to expect such things in distributed files or when there is nobody else using your system, but it also helps "protect you from yourself" in some instances. Of course, as root on your own machine, it's up to you :-) -- Josh -- ____________------------===========------------____________ from: Josh Kopper jjk1@lehigh.edu Computer Engineering, CSEE Department, Lehigh University Systems Programming - Lehigh University Computing Center
| Greg Kroah-Hartman | [PATCH 001/196] Chinese: Add the known_regression URI to the HOWTO |
| Linus Torvalds | Linux 2.6.27-rc8 |
| James Bottomley | Re: Integration of SCST in the mainstream Linux kernel |
| Greg KH | Linux 2.6.25.10 |
git: | |
| Sverre Rabbelier | Git vs Monotone |
| Robert Collins | Re: VCS comparison table |
| Junio C Hamano | Re: git-diff on touched files: bug or feature? |
| Linus Torvalds | Re: [PATCH] Avoid running lstat(2) on the same cache entry. |
| Steve Shockley | Re: Real men don't attack straw men |
| chefren | Re: [Fwd: Open-Hardware] |
| ropers | Re: About Xen: maybe a reiterative question but .. |
| Leon Dippenaar | New tcp stack attack |
| David Miller | Re: [GIT]: Networking |
| Jeff Garzik | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| Ilpo Järvinen | Re: [bug] stuck localhost TCP connections, v2.6.26-rc3+ |
| Sangtae Ha | Re: A Linux TCP SACK Question |
