suexec suppose to guard you from unprivileged programs (among other things), by letting you configure a safe_path of execution. However, if a user is able to link, she can create a link to files outside of the safe_path and then execute them. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
- Re: [Full-Disclosure] suexec doesn't ignore links in saf... Guy Cohen
- Re: [Full-Disclosure] suexec doesn't ignore links i... Niels Bakker
- Re: [Full-Disclosure] suexec doesn't ignore lin... Guy Cohen
- Re: [Full-Disclosure] suexec doesn't ignore... Charles Stevenson
- Re: [Full-Disclosure] suexec doesn't ig... White Vampire
