[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Mldonkey-users] minor bug in allowed_commands?
From: |
Thomas de Grenier de Latour |
Subject: |
Re: [Mldonkey-users] minor bug in allowed_commands? |
Date: |
Fri, 14 Mar 2003 00:20:04 +0100 |
On Thu, 13 Mar 2003 15:36:14 +0100 (MET)
Sergio Bayarri Gausi <address@hidden> wrote:
>
> Hello,
>
> I have, in downloads.ini:
>
> allowed_commands = [
> (df, df);
> (ls, "ls incoming");]
>
> But if I do a "! ls" in the interface, the mldonkey directory (the one
> with the binaries, configuration files, ...) is listed, not the
> incoming directory.
It has been fixed in cvs 2.04rc1-3.
But now I wonder if this feature is really secure... If somebody gains
access to your mldonkey, won't he be able to change the value of the
allowed_commands option to execute whatever he wants?
--
Thomas.