lynx-dev
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: lynx-dev passing the authentication login/password via a file?


From: Dick Wesseling
Subject: Re: lynx-dev passing the authentication login/password via a file?
Date: Fri, 16 Apr 1999 18:28:33 +0200

address@hidden said:
> On Thu, 15 Apr 1999, Steven Sakata wrote:
> 
> > We are using "lynx" on a UNIX box to download files from a secure
> > site. We currently pass the login and password using the "-auth"
> > argument. It works well. However, my concern is that while it is
> > running, any user can do a "ps"

> I see two solutions to this problem.

A third solition would be to change the commandline displayed by "ps" 
if a -auth parameter is present. The trouble is that:

a) there is a race condition (but exploit is unlikely?)

b) this is system dependent. If anyone is interested, you can look into 
the Sendmail sources to see how it deals with changing the output of 
"ps" on the various flavours of unix.




reply via email to

[Prev in Thread] Current Thread [Next in Thread]