Re: Access to nfs server, Part 2

From: Kyle Maxwell (krmaxwell_at_gmail.com)
Date: 07/24/04

  • Next message: Alvin Oga: "Re: Hack attempt"
    Date: Fri, 23 Jul 2004 20:25:10 -0500
    To: Scott Gifford <sgifford@suspectclass.com>
    
    

    On Fri, 23 Jul 2004 12:14:05 -0400, Scott Gifford
    <sgifford@suspectclass.com> wrote:

    > This will only work if you're very careful of what commands you allow
    > them to run, and the commands are designed to be run with elevated
    > privileges. Otherwise the developer may be able to use command-line
    > options or interactive commands to get into a shell or otherwise run
    > arbitrary commands.

    Check out rvim (in Fedora it's part of the vim-minimal package and is
    likely found on other distros). From vim(1):

           Vim behaves differently, depending on the name of the command (the exe-
           cutable may still be the same file).

           rvim rview rgvim rgview
                     Like the above, but with restrictions. It will not be possi-
                     ble to start shell commands, or suspend Vim. Can also be
                     done with the "-Z" argument.

    Haven't used it but it's worth looking into.

    -- 
    Kyle Maxwell
    krmaxwell@gmail.com
    

  • Next message: Alvin Oga: "Re: Hack attempt"

    Relevant Pages

    • Re: [opensuse] Checkinstall dropped from Opensuse [Was: Compiling the Suse way]
      ... But then there is a large list listing every single file and directory that the rpm has to have. ... Only the developer of that library knows what needs to be included. ... Commands I can type, ... Even an advanced user. ...
      (SuSE)
    • Re: iPod Touch Update
      ... Theres a bible app that I got a fe days ago and the voice over ... touch commands that are active when voice over is on. ... There's no telling what crazy things a third-party developer will do, ...
      (comp.sys.mac.system)
    • Re: .net commands and tools
      ... > Is there a place (website/book) that I can use to see what are ... > "commands and tools" that are recommended to be used by the ... > .net 1.1 developer? ... Phill W. ...
      (microsoft.public.vstudio.general)
    • Re: [opensuse] Re: RTL8187 chipset
      ... documentation to the developer), i was asking if, given the code is offered ... To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx ... For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx ...
      (SuSE)
    • Re: Access to nfs server, Part 2
      ... > I am always leery of giving someone root access to any machine on my ... > network if I don't trust him on EVERY machine. ... This will only work if you're very careful of what commands you allow ... Otherwise the developer may be able to use command-line ...
      (Focus-Linux)