[Gllug] apt/dpkg woes

Chris Jones cmsj at tenshu.net
Thu Jun 28 10:30:44 UTC 2007


Hi

Pete Ryland wrote:
> In any case, an attacker wanting to run a script from these places can
> still just run "sh scriptname" anyway.

Indeed, or if it's a binary, something like:

/lib/ld-linux.so.2 /tmp/my_naughty_file

will work fine.

Cheers,
-- 
Chris Jones
  cmsj at tenshu.net
   www.tenshu.net
-- 
Gllug mailing list  -  Gllug at gllug.org.uk
http://lists.gllug.org.uk/mailman/listinfo/gllug




More information about the GLLUG mailing list