[Pkg-sysvinit-devel] Why is noclobber used in bootclean.sh?
Thomas Hood
jdthood at yahoo.co.uk
Mon Jan 9 22:17:47 UTC 2006
Miquel van Smoorenburg wrote:
> Well you must definitely do the rm, since otherwise an attacker could
> symlink /tmp/.clean to /etc/passwd, crash the system somehow, and then
> you'd end up with a very very small password file.
OK, I have restructured the script a bit for clarity, adding some comments
keeping both the rm and the noclobber for maximum safety.
--
Thomas
More information about the Pkg-sysvinit-devel
mailing list