On Fri, 24 Oct 2003 20:08:24 +0200, Sebastian Niehaus <[EMAIL PROTECTED]>  said:

> Well, if you have a programm to be run in suid mode, every Unix admin
> should be alerted. They are used to review the source code of this
> kind of stuff.

When was the last time you audited the source for 'ping' or 'traceroute'?

Is there *anybody* qualified to do an audit of /usr/X11R6/bin/XFree86?

Attachment: pgp00000.pgp
Description: PGP signature

Reply via email to