[PATCH] prevent users from changing their environment

Ben Lindstrom mouring at etoh.eviladmin.org
Fri Jul 26 05:54:01 EST 2002


On Thu, 25 Jul 2002, Carson Gaspar wrote:

>
>
> --On Thursday, July 25, 2002 2:16 PM -0500 Ben Lindstrom
> <mouring at etoh.eviladmin.org> wrote:
>
> > Why are you using a restricted shell that is not staticly compiled?  That
> > is asking for trouble.  I don't see why we need to apply this to work
> > around an issue with an incorrect configuration you have decided to use.
>
> Just try to build a completely statically linked binary under Solaris.
>

Then it is an OS defect.  My point still holds true.

Of course this all begs to ask.. "Why do you allow them to muck around in
~/.ssh/ to start with?!"  Refer back to the chroot() + sftp/ssh arguments
that occur ever 3 - 4 months on this list.

> And take a nap or something - you're sounding really grouchy.
>

<shrug> This should shows you that reading into emails is a bad thing.
Normally reading me even in person is not even advise. <weak smile>

I'm actually in a good mood.  I have new hardware to deploy at home
for OpenSSH project.

Now, if I could only arrange to pick up my Indy that I the traded my
SS20 for. I'll be extremely happy.  Hopefully this weekend.  Otherwise
next month. <sigh>

- Ben




More information about the openssh-unix-dev mailing list