Re: .exrc file security risks
"Benjamin A. Okopnik" <[email protected]>
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Apr 30, 2003 at 08:09:49AM -0400, Reg Quinton wrote: > > external commands. So you have the situation where if a .exrc file is > > compromised, a key could be maped to perform any command as the user > running > > vi... > > By the same token. If .login, .cshrc, .profile, etc. are compromised then > you have similar issues -- you've lost control of your environment. > > Does anyone recommend one not use these files? There's a cautionary note in the Vim help files that has to do with ".exrc" files in directories other than $HOME; those get read as default behavior unless "secure" is set in EXINIT or "~/.exrc" (note that this is standard for "vim"; I _believe_ it's also standard for "vi" but have no way to test at the moment.) A user opening up an untrusted tarball is all it would take. Ben Okopnik -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Linux: The OS people choose without $200,000,000 of persuasion. -- Mike Coleman