More into /etc/rc.d/jail

Thordur I. Bjornsson thib at mi.is
Fri Aug 12 18:22:33 GMT 2005


On Wed, 10 Aug 2005 00:08:09 +0200
"Simon L. Nielsen" <simon at FreeBSD.org> wrote:

> On 2005.08.09 23:30:26 +0200, Stefan Bethke wrote:
> 
> > Am 09.08.2005 um 21:10 schrieb drvince at Safe-mail.net:
> [...]
> > 	sed -e 's/#.*$//' <${mdconfig_conf} |grep -v '^[[:space:]]*$'
> > 	>/tmp/mdconfig.$$
> 
> Try searching the web for "temporary file symlink attack"... (hint:
> creating temorary files like that is bad, use mktemp).
> 
> -- 
> Simon L. Nielsen
> 
I just like to point out the 'nosymfollow' mount option. Good stuff :)

-- 
Thordur I.	<bzthib at gmail.com>
Humppa!


More information about the freebsd-current mailing list