Re: Command injection in /etc/rc.d/netif
| Newsgroups | gmane.os.freebsd.security.general,gmane.os.freebsd.bugs |
|---|---|
| Message-ID | <JtbO7cb96mDblwMaGVVBvFaxDWJORiWtjHFegdR82wCKd88knU7VqRdhrBK35KQ1qxXDZ5X7HCQOH88dElc2V71pya_JL3f-hsdT5yNyTiw=@proton.me> |
hello why is this a security issue, if an unauthenticated user has permission to modify an rc script then that's on the sysadmin that gave such permission,not on the system,and i don't see any realistically possible scenario where without explicit consent from the root user to modify a rc script as such someone would maliciously be able to be modify as such, and if someone is explicitly allowed to modify a rc script as such then at that point that's not an issue about how the rc script is written it's about trust as you can make a shell script that launches at boot do anything, so clarify please what's wrong with the rc script?