Scary .desktop behaviour

David Mandelberg mandelbergd at eth0.is-a-geek.org
Wed Jan 19 19:14:39 CST 2005


Sivan Green wrote:
> Maybe add / modify the makefiles to chmod all the desktop
> files? :-)
How about only doing it to files that don't match this pcre:
/\<rm\>[\-\sa-zA-Z0-9]*\s(\$|.*\/.*)/ ? This could be outwitted by using eval
and sed or symlinks, but as there are no know exploits yet...

--
-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GAT/CM$/CS>$/CC/IT$/M/S/O/U dpu s+:++ !a C++$>C+++$
UB+++>++++$L++++$*-- P+>++$ L+++(++++)$ E-(---) W+++>$ N(+) o? K-
w--(---) O? M V? PS++@ PE-@ Y+@ PGP++(+++)>$ t? 5? X? R tv--(-)
b++(+++)@ DI? D? G e->++++ h* r? z*
------END GEEK CODE BLOCK------

David Mandelberg
mandelbergd at eth0.is-a-geek.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 256 bytes
Desc: OpenPGP digital signature
Url : http://lists.ubuntu.com/archives/ubuntu-devel/attachments/20050119/03f0fae4/signature.pgp


More information about the ubuntu-devel mailing list