GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Jan Schaumann (jschauma@mstdn.social)'s status on Thursday, 09-Jan-2025 08:34:10 JST Jan Schaumann Jan Schaumann

    "/bin/sh: the biggest #UNIX security loophole", by James A. Reeds, 1984

    https://www.tuhs.org/Archive/Documentation/TechReports/Bell_Labs/ReedsShellHoles.pdf

    All the tried and true ways to escalate privileges, including your common shell-out of setuid programs, PATH games, etc. with the conclusion we still see people having to learn repeatedly:

    In conversation about a year ago from mstdn.social permalink

    Attachments


    1. https://media.mstdn.social/media_attachments/files/113/794/849/555/105/152/original/c1cbe61ac02770a7.png
    • Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      sirjofri@mastodon.sdf.org's status on Thursday, 09-Jan-2025 08:34:37 JST sirjofri sirjofri
      in reply to

      @jschauma sh even has a weird syntax, especially if compared to rc.

      Funny story: I recently wrote a few imagemagick scripts. All sources complain about quoting and escaping. I had no issues like that with rc!

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.