Re: Command injection in /etc/rc.d/netif

[email protected]
Newsgroups gmane.os.freebsd.security.general,gmane.os.freebsd.bugs
Message-ID <JtbO7cb96mDblwMaGVVBvFaxDWJORiWtjHFegdR82wCKd88knU7VqRdhrBK35KQ1qxXDZ5X7HCQOH88dElc2V71pya_JL3f-hsdT5yNyTiw=@proton.me>
hello why is this a security issue, if an unauthenticated user has permission to modify an rc script then that's on the sysadmin that gave such permission,not on the system,and i don't see any realistically possible scenario where without explicit consent from the root user to modify a rc script as such someone would maliciously be able to be modify as such, and if someone is explicitly allowed to modify a rc script as such then at that point that's not an issue about how the rc script is written it's about trust as you can make a shell script that launches at boot do anything, so clarify please what's wrong with the rc script?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.