Hi,
aide uses a very predictable name in tmp (/tmp/empty/aide.db) with the
assumption that it will give an error because the file does not exist.
A malicious user can easily create /tmp/empty and place a dummy db in
there and thus disrupt or even negate the effect of aide.
If you want to force people to configure your package before use then
please do use something reliably absent. Never use a static file in a
world writable place.
MfG
Goswin
--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]