[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Use $DEB_BUILD_DIR rather than parent directory?



>>>>> "Joey" == Joey Hess <joeyh@debian.org> writes:
    Joey> Please explain how, if you manage to get my shell to set an
    Joey> environement variable, you could not have just done whatver
    Joey> setting the environement variable eventually makes some
    Joey> program do?

If I can compromise some script used to setup an environment from
which you inherit your environment and you're not deliberately and
methodically building your environment from scratch, then I can place
anything I like in your environment.  This does not automatically
require a local-root compromise, although it does require careless
administration.

    Joey> (It would also be nice if you explained how environement
    Joey> variables can be hidden.)

Everything is hidden until someone looks for it.  You're assuming that
people look by default, 'jpenny' is assuming they don't.

-- 
Stephen

"If I claimed I was emperor just cause some moistened bint lobbed a
scimitar at me, they'd put me away"



Reply to: