SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Technology Stocks : Intel Corporation (INTC) -- Ignore unavailable to you. Want to Upgrade?


To: Gary Ng who wrote (40073)11/11/1997 11:10:00 PM
From: Elmer  Read Replies (1) | Respond to of 186894
 
Gary,
Why can't the system admin simply deny execute privileges to
any directory the user has write privileges to? This would stop a
user from executing any user uploaded code.

EP



To: Gary Ng who wrote (40073)11/12/1997 12:25:00 PM
From: Fridrik Skulason  Read Replies (2) | Respond to of 186894
 
>I never said Linus/FreeBSD is bullet proof but this bug
>turn them into a UNIX that cannot have any terminal/telnet
>access at all. You just don't know when someone would
>do the above.

Anybody wanting to crash such a system can do so already - without using this bug ... that's the point - this bug does not really change anything, as there are already numerous ways a malicious user can crash such a system - the easiest way for a non-privileged program would probably be a fork/malloc bomb, but many other ways are possible.