Re: "make report" - Mailing list pgsql-hackers

From Curt Sampson
Subject Re: "make report"
Date
Msg-id Pine.NEB.4.43.0204231716480.445-100000@angelic.cynic.net
Whole thread Raw
In response to Re: "make report"  (cbbrowne@cbbrowne.com)
List pgsql-hackers
On Tue, 23 Apr 2002 cbbrowne@cbbrowne.com wrote:

> Suggestion: Why not embed this information into the binary, and
> provide some way of extracting it.

I like this!

> [Downside: "Announcement, script kiddies: If you find option
> UPDATE_DESCR_TABS=1 in the configuration information, then there's a
> very easy root exploit..."]

That's not a downside at all. If an exploit exists, you need only
try it, and it works or it doesn't.

In fact, it's an upside becuase it allows someone who doesn't have
exploit code more easily to determine whether or not he might be
vulnerable.

cjs
-- 
Curt Sampson  <cjs@cynic.net>   +81 90 7737 2974   http://www.netbsd.org   Don't you know, in this new Dark Age, we're
alllight.  --XTC
 



pgsql-hackers by date:

Previous
From: Martijn van Oosterhout
Date:
Subject: Re: Documentation on page files
Next
From: Curt Sampson
Date:
Subject: Re: Documentation on page files