On Sat, Apr 18, 1998 at 07:29:19PM -0700, Robert Woodcock wrote: > I'd like to see this patch become the default: > > --- ircii-4.4/source/dcc.c~ Thu Dec 25 17:36:09 1997 > +++ ircii-4.4/source/dcc.c Sat Apr 18 19:22:43 1998 [patch body removed] > > Yes, what that does is check your /dcc commands to see if they have /etc > or /passwd in them, and if they do, print a message "Send request > rejected".
Ick, no. If an admin is not running shadow passwds, that's their fault. Don't cripple the user needing help with a file in /etc. [..] > My thoughts on this are that large systems without shadow passwords with > shell accounts with ircii installed are: > > 1. very few and far between. > > 2. probably not running debian. > > 3. have hundreds of other security holes because of #2, making this one > irrelevant. > > 4. have admins who usually wouldn't get debianized source anyway, or if > they did, they'd be clueful enough to "fix" it. > > I'd love to hear people's opinions on this. Quite true on all counts. I see no need for the patch.
pgpMdyzi94EaS.pgp
Description: PGP signature