Re: .exrc file security risks

"Benjamin A. Okopnik" <[email protected]>
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
On Tue, Apr 29, 2003 at 09:04:12PM -0400, Ben Okopnik wrote:
> 
> The autoloading of the per-directory .exrc files (and shell escape/write
> commands in them) can be disabled by invoking the "secure" command in
> "/etc/exrc".

Whoops, my mistake - forget "/etc/exrc", no such thing under Solaris. :)
System-wide "vi" stuff usually gets set via EXINIT in "/etc/profile".


Ben Okopnik
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
"We have enough religion to hate each other, but not enough to
love each other."
 -- Jonathan Swift
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.