On Sep 10, Tom Lees <[EMAIL PROTECTED]> wrote:

 >Terminal devices [1]                          root.tty 0666
This is obviously wrong, ttys must have 620 permissions (or 600 if you
don't want people talk(1)ing to you, but I think the default should be
to allow it).
It's a huge security hole because with a ioctl you can inject commands
into shells not owned by you.

-- 
ciao,
Marco



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to