From owner-freebsd-current@FreeBSD.ORG Tue Aug 9 22:08:11 2005 Return-Path: X-Original-To: freebsd-current@freebsd.org Delivered-To: freebsd-current@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CC63316A41F for ; Tue, 9 Aug 2005 22:08:11 +0000 (GMT) (envelope-from simon@zaphod.nitro.dk) Received: from zaphod.nitro.dk (port324.ds1-khk.adsl.cybercity.dk [212.242.113.79]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5FCB243D58 for ; Tue, 9 Aug 2005 22:08:11 +0000 (GMT) (envelope-from simon@zaphod.nitro.dk) Received: by zaphod.nitro.dk (Postfix, from userid 3000) id C903A119EB; Wed, 10 Aug 2005 00:08:09 +0200 (CEST) Date: Wed, 10 Aug 2005 00:08:09 +0200 From: "Simon L. Nielsen" To: Stefan Bethke Message-ID: <20050809220809.GD928@zaphod.nitro.dk> References: <96153776-0BE4-456F-B573-042E84730DFE@lassitu.de> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="TiqCXmo5T1hvSQQg" Content-Disposition: inline In-Reply-To: <96153776-0BE4-456F-B573-042E84730DFE@lassitu.de> User-Agent: Mutt/1.5.9i Cc: drvince@anonymnet.net, freebsd-current@freebsd.org Subject: Re: More into /etc/rc.d/jail X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 09 Aug 2005 22:08:11 -0000 --TiqCXmo5T1hvSQQg Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2005.08.09 23:30:26 +0200, Stefan Bethke wrote: > Am 09.08.2005 um 21:10 schrieb drvince@Safe-mail.net: [...] > sed -e 's/#.*$//' <${mdconfig_conf} |grep -v '^[[:space:]]*$' >/tmp/mdco= nfig.$$ Try searching the web for "temporary file symlink attack"... (hint: creating temorary files like that is bad, use mktemp). --=20 Simon L. Nielsen --TiqCXmo5T1hvSQQg Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.1 (FreeBSD) iD8DBQFC+SlJh9pcDSc1mlERAhjTAKC4nGMVyCxPp3nUn8OUlRGQqbCw7wCgpQfY f4sSi/Jxsskb6/OdBps/bS8= =2j3E -----END PGP SIGNATURE----- --TiqCXmo5T1hvSQQg--