lynx-dev
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Fwd: BoS: A vulnerability in Lynx (all versions)] LYNX-DEV


From: Klaus Weide
Subject: Re: [Fwd: BoS: A vulnerability in Lynx (all versions)] LYNX-DEV
Date: Wed, 7 May 1997 10:29:19 -0500 (CDT)

On Wed, 7 May 1997, Nelson Henry Eric wrote:

> > # Don't use without modification for an anonymous (captive) guest account!

> Any pointers on what to watch out for / how to modify greatly appreciated.

That was just a strong disclaimer because I really don't know all the
things necessary in that situation (environment variables, lynx
options, how to set up the account, ...).  I am sure you already know
those things much better.


> > LYNX_TEMP_SPACE=/tmp/LY$$-$USER
> 
> I've found that I need to set LYNX_TEMP_SPACE to a subdirectory of $HOME
> so that I don't have one student hogging the whole disk.  Would there be
> some hidden danger to modifying that to:
> 
>       LYNX_TEMP_SPACE=/$HOME/LY$$-$USER  ?
>                        ^^^^^

Not that I know.  But if you have already set up things such that temp
files are in directories under $HOME, then you are already preventing
the problem described.  (assuming normal use of permissions.)  So the
only thing this would give you is that you don't have to create those
directories when setting up new accounts, and the removal of those
dirs (if the trap comand works for you as when I tested it).

I was thinking more of systems that would *want* temp files to be under
/tmp/, so that temporary files don't lie around indefinitely in user
directories if something goes wrong (assuming old files in /tmp/ get
removed automatically).

   Klaus

;
; To UNSUBSCRIBE:  Send a mail message to address@hidden
;                  with "unsubscribe lynx-dev" (without the
;                  quotation marks) on a line by itself.
;

reply via email to

[Prev in Thread] Current Thread [Next in Thread]