/etc/profile sets the global path and any of several files may set your specific path, such as ~/.bash_profile, ~/.bash_login, ~/.profile and, if not a login shell or otherwise accessed, ~/.bashrc.
But the current directory is explicitly placed in the path of non-root users in the original Slack /etc/profile. Had it been altered, anyone or anything with root permissions could change your path and anything with those or your permissions could change your own files. That would be uncool, at best, though.
|