Re: .exrc file security risks
"Benjamin A. Okopnik" <[email protected]>
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Apr 29, 2003 at 09:04:12PM -0400, Ben Okopnik wrote: > > The autoloading of the per-directory .exrc files (and shell escape/write > commands in them) can be disabled by invoking the "secure" command in > "/etc/exrc". Whoops, my mistake - forget "/etc/exrc", no such thing under Solaris. :) System-wide "vi" stuff usually gets set via EXINIT in "/etc/profile". Ben Okopnik -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- "We have enough religion to hate each other, but not enough to love each other." -- Jonathan Swift