Bugtraq mailing list archives

Re: jj.c


From: daveg () escape com (Dave G.)
Date: Wed, 25 Dec 1996 00:32:17 -0500


I have looked at this before, and tilde escaping from /bin/mail shouldn't
work on most modern systems simply because the /bin/mail's I have looked
at dont accept tilde escapes unless the the input is coming from a terminal,
or /bin/mail is invoked with -I.


Regardless, jj is a great example of how to write insecure code.

So, is there any /bin/mail that will accept tilde escapes if the input
isn't coming from a terminal?

Dave G.
<daveg () escape com>
http://www.escape.com/~daveg



Current thread: