Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 7 Oct 2000 23:05:21 -0500 (CDT)
From:      Frank Tobin <ftobin@uiuc.edu>
To:        FreeBSD-Stable <stable@FreeBSD.ORG>
Subject:   Re: Security problem with "script"? 
Message-ID:  <Pine.BSF.4.21.0010072304100.17477-100000@localhost>
In-Reply-To: <200010072350.RAA00780@harmony.village.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Warner Losh, at 17:50 -0600 on Sat, 7 Oct 2000, wrote:

> Yes.  That's the logical conclusion if you give someone shell access,
> or access to any program that can fork a shell.  "TOYOTA: You asked
> for it, you got it."

Along the same lines, don't give a user sudo access to just run "xemacs",
unless you want them playing Tetris as root.  Oh, wait...that's not the
worst thing they can do :)

-- 
Frank Tobin		http://www.uiuc.edu/~ftobin/



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0010072304100.17477-100000>