Great Circle Associates Firewalls
(February 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: questions about security & WWW browsers
From: mccurley @ cs . sandia . gov (Kevin S. McCurley)
Date: Sat, 18 Feb 1995 00:48:18 -0700 (MST)
To: cwe @ it . kth . se (Christian Wettergren)
Cc: Brent @ greatcircle . com, bwalker @ shell . portal . com, firewalls @ greatcircle . com
In-reply-to: <199502180631 . HAA19549 @ tmpwww . electrum . kth . se> from "Christian Wettergren" at Feb 18, 95 07:31:49 am

> * dvi-files
>   dvips has "feature" of embedded shell commands, special("`|...")
>   I believe it was.

TeX also supports macros to manipulate files (e.g., \openout)

> * xv 
>   if filename starts with '!', execute the rest. '>' is also special.
>   When will Mosaic and other viewers start to obey the MIME filename
>   directives?

note also that at least one version of xv will execute the postscript
commands for manipulating files.

Perhaps it would be shorter to give a list of "safe" things.  Can anybody
think of one???

Kevin McCurley
Sandia National Laboratories



Follow-Ups:
References:
Indexed By Date Previous: Re: questions about security & WWW browsers
From: Christian Wettergren <cwe @ it . kth . se>
Next: Re: Source Routing...
From: Bernhard Schneck <Bernhard . Schneck @ GeNUA . DE>
Indexed By Thread Previous: Re: questions about security & WWW browsers
From: Christian Wettergren <cwe @ it . kth . se>
Next: Re: questions about security & WWW browsers
From: Christian Wettergren <cwe @ it . kth . se>

Google
 
Search Internet Search www.greatcircle.com