The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security
Google UNIX.COM



Thread: Security broken
View Single Post in UNIX Forums - Click on the Thread or Permalink to View Entire Thread -->
  #2 (permalink)  
Old 02-24-2007
Perderabo's Avatar
Perderabo Perderabo is offline
Unix Daemon
 

Join Date: Aug 2001
Location: Washington DC Area
Posts: 8,354
Not much info here. But I will make a wild guess. When your clients connect, they probably use an account with a regular shell, like /usr/bin/sh. Then you depend on a .profile or other start-up file to send them to your application. If they hit interrupt fast enough, they can break out of the .profile. If this is your setup, you should change it. Make your application their shell. Then they go straight to it and there is no regular shell for them to break into.
Reply With Quote