Re: .exrc file security risks

"Benjamin A. Okopnik" <[email protected]>
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
On Wed, Apr 30, 2003 at 08:09:49AM -0400, Reg Quinton wrote:
> > external commands.  So you have the situation where if a .exrc file is
> > compromised, a key could be maped to perform any command as the user
> running
> > vi...
> 
> By the same token. If .login, .cshrc, .profile, etc. are compromised then
> you have similar issues -- you've lost control of your environment.
> 
> Does anyone recommend one not use these files?

There's a cautionary note in the Vim help files that has to do with
".exrc" files in directories other than $HOME; those get read as default
behavior unless "secure" is set in EXINIT or "~/.exrc" (note that this
is standard for "vim"; I _believe_ it's also standard for "vi" but have
no way to test at the moment.) A user opening up an untrusted tarball is
all it would take.


Ben Okopnik
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Linux: The OS people choose without $200,000,000 of persuasion.
 -- Mike Coleman
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.