Re: /bin/pwd

Sam Steingold <[email protected]>
Newsgroups gmane.lisp.clisp.devel
Message-ID <[email protected]>
Hi,

> * Tomas Hlavaty <[email protected]> [2016-08-30 09:17:33 +0200]:
> Sam Steingold <[email protected]> writes:
>> running external programs without a full path is a security risk.
>
> What is the reasoning behind this assertion?

* if clisp executes "pwd" and
* you have, say, "~/bin" in your $PATH before "/bin" and
* a malicious actor plants an executable named "pwd" into "~/bin", then
  you will run that executable as yourself.

-- 
Sam Steingold (http://sds.podval.org/) on darwin Ns 10.3.1404
http://www.childpsy.net/ http://honestreporting.com http://think-israel.org
http://iris.org.il http://thereligionofpeace.com http://islamexposedonline.com
Abandon all hope, all ye who press Enter.

------------------------------------------------------------------------------
_______________________________________________
clisp-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/clisp-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.