[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: SECURITY PROBLEM: autofs [all versions]



On Fri, 7 Jul 2000, Christopher W. Curtis wrote:

> Adam Heath wrote:
> > 
> > On Fri, 7 Jul 2000, Christopher W. Curtis wrote:
> > 
> > > Herbert Xu wrote:
> > > >
> > > > It's not wrong at all.  In fact, doing a -x will only mislead people into
> > > > believing chmod -x actually works as a way of disabling something, which it
> > > > doesn't.
> > >
> > > Then there should be no test at all because a -f would lead people to
> > > believe that removing (or renaming) the file is the correct way to
> > > disable something, which it isn't any more than chmod -x as it suffers
> > > the same problem.
> > 
> > man dpkg-divert
> 
> What?
> 
> How is that relevant?

Read the man page on it, and find out.

You can create your own file, in place of portmap.  Any deb that will then try
to install portmap, will have this be redirected to another file.  So, your
own personally created portmap can be a shell wrapper script, of some type.

Or, even better, you can just not have a portmap, but have it diverted
elsewhere.

----BEGIN GEEK CODE BLOCK----
Version: 3.12
GCS d- s: a-- c+++ UL++++ P+ L++++ !E W+ M o+ K- W--- !O M- !V PS--
PE++ Y+ PGP++ t* 5++ X+ tv b+ D++ G e h*! !r z?
-----END GEEK CODE BLOCK-----
----BEGIN PGP INFO----
Adam Heath <doogie@debian.org>        Finger Print | KeyID
67 01 42 93 CA 37 FB 1E    63 C9 80 1D 08 CF 84 0A | DE656B05 PGP
AD46 C888 F587 F8A3 A6DA  3261 8A2C 7DC2 8BD4 A489 | 8BD4A489 GPG
-----END PGP INFO-----



Reply to: