[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: A little ircii /dcc tweak I'd like to see the default...



On Sat, Apr 18, 1998 at 07:29:19PM -0700, Robert Woodcock wrote:
> I'd like to see this patch become the default:
> 
> --- ircii-4.4/source/dcc.c~	Thu Dec 25 17:36:09 1997
> +++ ircii-4.4/source/dcc.c	Sat Apr 18 19:22:43 1998
[patch body removed]
> 
> Yes, what that does is check your /dcc commands to see if they have /etc
> or /passwd in them, and if they do, print a message "Send request
> rejected".

Ick, no.  If an admin is not running shadow passwds, that's their fault.
Don't cripple the user needing help with a file in /etc.

[..]
> My thoughts on this are that large systems without shadow passwords with
> shell accounts with ircii installed are:
> 
> 1. very few and far between.
> 
> 2. probably not running debian.
> 
> 3. have hundreds of other security holes because of #2, making this one
>    irrelevant.
> 
> 4. have admins who usually wouldn't get debianized source anyway, or if
>    they did, they'd be clueful enough to "fix" it.
> 
> I'd love to hear people's opinions on this.

Quite true on all counts.  I see no need for the patch.

Attachment: pgpiGpXK23ycO.pgp
Description: PGP signature


Reply to: