OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Doscmd
From: Bill Fumerola (billfchc-chimes.com)
Date: Wed Feb 16 2000 - 00:13:04 CST


On Tue, Feb 15, 2000 at 08:56:41PM -0800, Kuzak wrote:

> A friend of mine was asking me about an exploit
> for 3.4-STABLE.. and I wasn't quite sure about
> the answer.. Basically is it safe to disable
> /usr/bin/doscmd ( chmod 000 /usr/bin/doscmd ),
> and will this render this exploit useless?

doscmd isn't suid to begin with, so I don't see the problem.

I could be missing the point though.

doscmd however can be safely disabled or removed without
any negative effect.

-- 
Bill Fumerola - Network Architect
Computer Horizons Corp - CVM
e-mail: billfchc-chimes.com / billfFreeBSD.org
Office: 800-252-2421 x128 / Cell: 248-761-7272

To Unsubscribe: send mail to majordomoFreeBSD.org with "unsubscribe freebsd-security" in the body of the message