Quoting "Stephane Chazelas" <stephane.chaze...@gmail.com>:

I understand what you're saying.
As much as we would like, there's no way of stopping all attack vectors by only hardening bash, not only that, but also taking away its useful features.
Though I still believe PS4 shouldn't be imported from the environment.

Should we also block SHELLOPTS=history
HISTFILE=/some/file like /proc/$pid/fd/$fd and
TZ=/proc/$pid/fd/$fd (like for your /bin/date command) as that
allows DoS on other processes (like where those fds are for
pipes).

Mind explaining this one?
I can't seem to write to HISTFILE in a non-interactive shell, or am i missing something?

Thanks.


----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.



Reply via email to