Re: Security setup

From: Mike Ayers
Subject: Re: Security setup
Date: Tue, 17 Dec 2002 22:10:06 -0800
User-agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.2.1) Gecko/20021130

Larry Jones wrote:

Once you're connected to a pserver, it's a fairly simple process to get
it to execute arbitrary commands for you; giving someone pserver access
is equivalent to giving them shell access.


The above applies to *any* kind of client/server mode, not just pserver.

Let me make sure of this. You're saying that even when running only over ssh, in a jail, with a login shell of cvs, someone can still get shell access?

        If I am misunderstanding, please clarify.



