Re: Annoucement: Local Browser Execution

Philippe-Andre Prindeville <philipp@res.enst.fr>
Organization: Ecole Nationale Superieure des Telecommunications, Paris
Date: Tue, 14 Dec 93 13:53:18 +0100
From: Philippe-Andre Prindeville <philipp@res.enst.fr>
Message-id: <9312141353.ZM13836@clarke.res.enst.fr>
In-Reply-To: George Phillips <phillips@cs.ubc.ca>
        "Annoucement: Local Browser Execution" (Dec 13, 17:36)
References: <199312140136.AA12547@grolsch.cs.ubc.ca>
X-Address: 	E.N.S.T. - Dept. Res. / 46, rue Barrault / 75634 Paris Cedex 13
 		Tel +33(1) 45.81.73.14  Fax +33(1) 44.16.70.20
X-Face: >4WM/$ED&E'4zy#c4]"b5^50kZ9W\o}W+e>qU0!;~b|q/.dFb}M4JKOu_gIL[`Zb!=\(t<$
 	ZoARNta[Qx:";t-A0-l$=tBB=bPzZpsUnUQ*8ZPHUV<GA1eqB<H~4]}+[v|G1M<2j9Dr+u}
 	po*F``aQzl"_rtwP5l`GKH}aHuh4=%U/JGO.HeYDoR.#?+iS0{'iglw`6|4T[rWVz*=0i(
X-Mailer: Z-Mail (2.1.5 20sep93)
To: George Phillips <phillips@cs.ubc.ca>, www-talk@nxoc01.cern.ch
Subject: Re: Annoucement: Local Browser Execution
On Dec 13, 17:36, George Phillips wrote:
> Subject: Annoucement: Local Browser Execution

> One last thing.  I'm certainly interested in discussing viable
> alternatives to x-exec: and suggestions for improving it.  Flames
> about it being "a bad thing" and/or "the wrong thing" will be
> accepted in the same cheerful spirit as Mosaic Motif flames.

I'm not saying it is a "bad" or "wrong" thing.  But it has to be
pointed out that the possibility for Trojan Horses here is
mind-boggling.  One of the students here had FTP'd a shar file
from a BBS that he thought contained pornographic images.  When
he ran it, it archived and encrypted his directory and told him
where you could send $50 to get the password to unencrypt his files.

Serves him right, I said to myself (not because I'm a moralist
crusading against pornography -- just because you have to be
pretty bleeding daft to run an untrusted shar file in your home
directory).

So, does your patch try to use a restricted shell?  If so, what
commands do you limit the agent to?  Do you chroot to a temporary
directory?

-Philip