From owner-cvs-usrsbin Fri Oct 11 02:46:57 1996 Return-Path: owner-cvs-usrsbin Received: (from root@localhost) by freefall.freebsd.org (8.7.5/8.7.3) id CAA03605 for cvs-usrsbin-outgoing; Fri, 11 Oct 1996 02:46:57 -0700 (PDT) Received: from sovcom.kiae.su (sovcom.kiae.su [193.125.152.1]) by freefall.freebsd.org (8.7.5/8.7.3) with SMTP id CAA03484; Fri, 11 Oct 1996 02:40:21 -0700 (PDT) Received: by sovcom.kiae.su id AA09666 (5.65.kiae-1 ); Fri, 11 Oct 1996 12:26:24 +0300 Received: by sovcom.KIAE.su (UUMAIL/2.0); Fri, 11 Oct 96 12:26:23 +0300 Received: (from ache@localhost) by nagual.ru (8.7.6/8.7.3) id NAA00448; Fri, 11 Oct 1996 13:17:44 +0400 (MSD) Message-Id: <199610110917.NAA00448@nagual.ru> Subject: Re: cvs commit: src/usr.sbin/ppp command.c In-Reply-To: <199610110741.JAA04262@uriah.heep.sax.de> from "J Wunsch" at "Oct 11, 96 09:41:23 am" To: joerg_wunsch@uriah.heep.sax.de Date: Fri, 11 Oct 1996 13:17:44 +0400 (MSD) Cc: sos@freefall.freebsd.org, CVS-committers@freefall.freebsd.org, cvs-all@freefall.freebsd.org, cvs-usrsbin@freefall.freebsd.org From: "=?KOI8-R?Q?=E1=CE=C4=D2=C5=CA_=FE=C5=D2=CE=CF=D7?=" (Andrey A. Chernov) Organization: self X-Class: Fast X-Mailer: ELM [version 2.4ME+ PL28 (25)] Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: owner-cvs-usrsbin@FreeBSD.ORG X-Loop: FreeBSD.org Precedence: bulk > As Soren Schmidt wrote: > > sos 96/10/10 04:27:38 > > > > Modified: usr.sbin/ppp command.c > > Log: > > Allow shell commands in all modes. > > Do you get a root shell now if you run ``ppp -auto'', connect to port > 3000, and issue a `shell'? I would consider this a very bad move! > Yes, we just make security hole, it should be fixed. telnet localhost ppp passwd xxx shell cat /etc/passwd works and shouldn't. -- Andrey A. Chernov http://www.nagual.ru/~ache/