OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: .exrc file security risks

From: Reg Quinton (reggersist.uwaterloo.ca)
Date: Wed Apr 30 2003 - 07:09:49 CDT


> external commands. So you have the situation where if a .exrc file is
> compromised, a key could be maped to perform any command as the user
running
> vi...

By the same token. If .login, .cshrc, .profile, etc. are compromised then
you have similar issues -- you've lost control of your environment.

Does anyone recommend one not use these files?