OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: aaa_base still vulnerable after upgrade
From: Horst von Brand (vonbrandSLEIPNIR.VALPARAISO.CL)
Date: Mon May 01 2000 - 09:57:48 CDT


Marc Heuse <marcSUSE.DE> said:

[...]

> > touch "/tmp/x /etc/rc.config"

> btw have you ever tried out this command? It won't work. A filename is not
> allowed to have a slash in it's name ...

True. But spaces are legal... this is file etc/rc.config inside directory
"x " inside /tmp

Note that Red Hat duistributes a binary called tmpwatch (written by them
and GPL) which safely deletes /tmp entries. Quite old, AFAIKT.

--
Horst von Brand                             vonbrandsleipnir.valparaiso.cl
Casilla 9G, Viņa del Mar, Chile                               +56 32 672616