OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: so, just how many library environment variables can specify filnames????? (was: Addition to force open to open only regular files)
From: Andrew Brown (atatatatatdot.net)
Date: Tue Nov 21 2000 - 12:23:02 CST


>: >But that's insanely unsafe. I believe that FreeBSD allows setting TZ
>: >only if it isn't an absolute path. This is a good compormise between
>: >allowing any old file to be read, and hopefully not disclosed and the
>: >extreme pita that not being able to set it.
>:
>: that's totally boneheaded. it completely breaks, for example, this:
>: % zdump /usr/share/zoneinfo/US/*
>
>Do it doesn;t, you bonehead! zdump isn't setuid.

okay, just for setuid things. good. too much coffee.

>: since all zdump does is continually reset the TZ environment variable.
>: it's not a good compromise, since then the time zone you're in depends
>: on the directory you're in. that's silly. libc already (afaict)
>
>No it doesn't. TZ=Asia/Tokyo doesn't depend on what dir you are in.

that one, no, since it's under /usr/share/zoneinfo. for files that
are *not* under /usr/share/zoneinfo, you have to specify an absolute
path.

>Before launching into inane attack, at least get your facts correct.

yes, sorry. i was a mite confused. hmm...i wonder if i can coerce
crontab into doing something evil with a TZ variable...

-- 
|-----< "CODE WARRIOR" >-----|
codewarriordaemon.org             * "ah!  i see you have the internet
twofsonetgraffiti.com (Andrew Brown)                that goes *ping*!"
andrewcrossbar.com       * "information is power -- share the wealth."