Re: Environment Poisoning and login -p

From: Jacques A. Vidrine (nectar_at_FreeBSD.org)
Date: 02/26/04

  • Next message: Mike Tancsa: "Re: HEADS UP: OpenSSH 3.8p1"
    Date: Thu, 26 Feb 2004 09:30:04 -0600
    To: kientzle@acm.org
    
    

    On Wed, Feb 25, 2004 at 10:54:31AM -0800, Tim Kientzle wrote:
    [...]
    > Possible fix: Have login unconditionally discard LD_LIBRARY_PATH
    > and LD_PRELOAD from the environment, even if "-p" is specified.
    [...]
    > Possible fix: Eliminate the "-p" option to login.

    I would prefer to redefine `-p' to mean, ``don't discard environmental
    variables believed to be safe to propogate''. We can start with this
    list:

    http://www.opengroup.org/onlinepubs/007904975/basedefs/xbd_chap08.html

    plus

        EDITOR
        KRB5CCNAME
        LOGIN
        MAILDIR
        SSH_AGENT_PID
        SSH_AUTH_SOCK
        TERMCAP

    If that is too draconian for you, then I guess just drop /LD_.*/.

    Put the `environment cleaner' in libutil.

    Cheers,

    -- 
    Jacques Vidrine / nectar@celabo.org / jvidrine@verio.net / nectar@freebsd.org
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Mike Tancsa: "Re: HEADS UP: OpenSSH 3.8p1"

    Relevant Pages

    • Re: "deborphan" is a wonderful utility
      ... that final upgrade as safe as possible. ... Just as a miscellaneous reference point, ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: On Access Virus Scanner Recommendation
      ... through NFS? ... but I'd like to be on the safe side. ... Are you aware of the potential threat that someone might trigger a ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: Aptitude losing "focus"
      ... Is that a safe thing to do? ... I don't know if it will noticeably hurt performance or not. ... has sent a patch to the bug log for a problem that is obvious now ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: /usr/lib/python2.3 in lenny
      ... be removed because it was not empty... ... is it safe to remove that directory manually? ... a few weeks ago from my Debian Etch system and have ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: whats the group and username of apache2 web server?
      ... but it is safe to change them. ... chmod -R 660 /var/www ... vulnerability in the web server exists. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)

    Loading