LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-06-2001, 11:59 AM   #1
gui10
Member
 
Registered: Mar 2001
Distribution: enigma, slack8
Posts: 677

Rep: Reputation: 30
regarding cat


i read somewhere (can't remember what, it's one of those linux books) that the command 'cat' presents a security compromise. the paper i read used plenty of techie jargon... if it's possible to, can anyone tell me in simple english how this is so?

===
out of context of post: to my amusement, after getting to use linux, there's now a 'cat' to go with the 'mouse' in my room... lol
===
 
Old 12-06-2001, 12:59 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
"Cat" doesn't need elevated privileges (read: privileges of another user) to perform its task, I never heard of a buffer overflow in cat, and I don't know what you've read.

I think you better post some excerpt from what youve read...

Last edited by unSpawn; 12-06-2001 at 01:01 PM.
 
Old 12-06-2001, 01:02 PM   #3
rshaw
Senior Member
 
Registered: Apr 2001
Location: Perry, Iowa
Distribution: Mepis , Debian
Posts: 2,692

Rep: Reputation: 45
could use it to pipe keystrokes (passwords) to a file. just a thought.
 
Old 12-06-2001, 04:23 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
IMO that *isn't* a risk in *cat* itself: it does what it is used for, catting something.
 
Old 12-07-2001, 07:32 AM   #5
gui10
Member
 
Registered: Mar 2001
Distribution: enigma, slack8
Posts: 677

Original Poster
Rep: Reputation: 30
the reason why i can't post up what i read (sorry about this, i know i'm coming across as vague) is coz i read it in a book in a bookshop... and i can't remember which one it is!!!

so thanks for all the contributions... i'll try to be less troublesome in the future...
 
Old 12-07-2001, 11:42 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Hell no! This aint troublesome.
For troublesome try backbilling a customer for one kool 500K and not finding any signed orders :-]
 
Old 12-07-2001, 08:09 PM   #7
gui10
Member
 
Registered: Mar 2001
Distribution: enigma, slack8
Posts: 677

Original Poster
Rep: Reputation: 30
Quote:
Hell no! This aint troublesome. For troublesome try backbilling a customer for one kool 500K and not finding any signed orders :-]
ho ho...
is that a personal experience? that must suck!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
less, cat, sed or what ebasi Linux - Software 8 07-28-2004 03:26 AM
My Cat unimaginative General 71 02-18-2004 01:08 PM
Cat ... Beuzekom Linux - Newbie 4 01-19-2004 05:32 PM
Any cat gurus in here? deepsix Linux - General 14 08-28-2003 09:41 AM
cat notsoevil Linux From Scratch 3 02-14-2002 10:16 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:47 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration