From owner-freebsd-security Wed May 29 16:54:41 2002 Delivered-To: freebsd-security@freebsd.org Received: from obsecurity.dyndns.org (adsl-64-169-107-187.dsl.lsan03.pacbell.net [64.169.107.187]) by hub.freebsd.org (Postfix) with ESMTP id 92A6C37B417; Wed, 29 May 2002 16:54:33 -0700 (PDT) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id 1F6B466B8B; Wed, 29 May 2002 16:54:33 -0700 (PDT) Date: Wed, 29 May 2002 16:54:32 -0700 From: Kris Kennaway To: cjclark@alum.mit.edu Cc: "Jacques A. Vidrine" , security@freebsd.org Subject: Re: FreeBSD Security Advisory FreeBSD-SA-02:27.rc Message-ID: <20020529165432.A8595@xor.obsecurity.org> References: <200205291636.g4TGaZX40801@freefall.freebsd.org> <20020529133852.B12700@blossom.cjclark.org> <20020529210334.GA5544@madman.nectar.cc> <20020529154113.D12700@blossom.cjclark.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="/9DWx/yDrRhgMJTb" Content-Disposition: inline User-Agent: Mutt/1.2.5.1i In-Reply-To: <20020529154113.D12700@blossom.cjclark.org>; from crist.clark@attbi.com on Wed, May 29, 2002 at 03:41:13PM -0700 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --/9DWx/yDrRhgMJTb Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, May 29, 2002 at 03:41:13PM -0700, Crist J. Clark wrote: > On Wed, May 29, 2002 at 04:03:34PM -0500, Jacques A. Vidrine wrote: > > On Wed, May 29, 2002 at 01:38:52PM -0700, Crist J. Clark wrote: > > > > /bin/sh -c 'echo -e "/.X11-unix/s/^/#/\nw\nq\n" | /bin/ed -s /et= c/rc' > > >=20 > > > Ick. How about, > > >=20 > > > # /usr/bin/printf "/.X11-unix/s/^/#/\nw\nq\n" | /bin/ed -s /etc/rc > > >=20 > > > Next time? > >=20 > > *shrug* One could prescribe any number of alternatives to achieve the > > modification. I chose this way, because /bin/sh and /bin/ed are both > > statically linked and should always be available on all systems in > > single user mode. It seems unlikely that this will be an issue for > > anyone, but hey - you never know. >=20 > I guess I should have explained my concern more. I'm thinking some > l33t kid out there is going to look at that and say, "I can just do, >=20 > # echo -e "/.X11-unix/s/^/#/\nw\nq\n" | /bin/ed -s /etc/rc >=20 > And not have to worry about all of that /bin/sh stuff at the front..." > and thus outsmart himself. If people are too stupid^Welite to follow directions they deserve what they get. Kris --/9DWx/yDrRhgMJTb Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (FreeBSD) iD8DBQE89Wo4Wry0BWjoQKURApFdAJ9PPtbAQRJmW06N1YpicfWjVW6nIwCgtAwQ oL4cqEDVJIFmmJcBM2atjl4= =bg0n -----END PGP SIGNATURE----- --/9DWx/yDrRhgMJTb-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message