Documents for paths

Code [path001w]

The indicated file is in root's PATH, and is group writable, world writable or both. This can allow Trojan horse programs or viruses to be planted into these executables and spread by `root'. The group and world write permissions should be removed.












Code [path002w]

The indicated file is in root's PATH, but is not owned by root. This can allow Trojan horse programs or viruses to be planted into these executables and spread by `root'. Often these executables are owned by `bin', `uucp' or other system accounts. If these commands are never used by root, then this is not a problem. If they are, you should consider changing the owner to `root'. Because of SMI's recent decission to install most /usr/sbin/MAKEDEV /usr/sbin/accessdb /usr/sbin/add-shell /usr/sbin/addgroup /usr/sbin/adduser /usr/sbin/ahorra-latex.old /usr/sbin/bacup /usr/sbin/badblocks /usr/sbin/blkid /usr/sbin/borra-formatos-de-tex /usr/sbin/borra-locales /usr/sbin/cfdisk /usr/sbin/chpasswd /usr/sbin/chroot /usr/sbin/cleanup-info /usr/sbin/clri.ufs /usr/sbin/cpgr /usr/sbin/cppw /usr/sbin/cron /usr/sbin/debugfs /usr/sbin/delgroup /usr/sbin/deluser /usr/sbin/dpasswd /usr/sbin/dpkg-divert /usr/sbin/dpkg-preconfigure /usr/sbin/dpkg-reconfigure /usr/sbin/dpkg-statoverride /usr/sbin/dumpe2fs /usr/sbin/e2fsck /usr/sbin/e2image /usr/sbin/e2label /usr/sbin/e2os /usr/sbin/editkeep /usr/sbin/exicyclog /usr/sbin/exim /usr/sbin/exim-upgrade-to-r3 /usr/sbin/exim_dbmbuild /usr/sbin/exim_dumpdb /usr/sbin/exim_fixdb /usr/sbin/exim_lock /usr/sbin/exim_tidydb /usr/sbin/eximconfig /usr/sbin/eximstats /usr/sbin/exinext /usr/sbin/exiqsumm /usr/sbin/exiwhat /usr/sbin/fdisk /usr/sbin/filefrag /usr/sbin/findfs /usr/sbin/fsck /usr/sbin/fsck.cramfs /usr/sbin/fsck.ext2 /usr/sbin/fsck.ext3 /usr/sbin/fsck.minix /usr/sbin/fsck.nfs /usr/sbin/fsck.ufs /usr/sbin/gnome-pty-helper /usr/sbin/groupadd /usr/sbin/groupdel /usr/sbin/groupmod /usr/sbin/grpck /usr/sbin/grpconv /usr/sbin/grpunconv /usr/sbin/grub /usr/sbin/grub-floppy /usr/sbin/grub-install /usr/sbin/grub-md5-crypt /usr/sbin/grub-terminfo /usr/sbin/halt /usr/sbin/harakiri /usr/sbin/harakiri-etc /usr/sbin/iconvconfig /usr/sbin/in.ftpd /usr/sbin/in.identtestd /usr/sbin/in.rexecd /usr/sbin/in.rlogind /usr/sbin/in.rshd /usr/sbin/in.tftpd /usr/sbin/in.uucpd /usr/sbin/inetd /usr/sbin/install-info /usr/sbin/install-sgmlcatalog /usr/sbin/installkernel /usr/sbin/ispell-autobuildhash /usr/sbin/ispellconfig /usr/sbin/ldconfig /usr/sbin/limpia-var-lib-dpkg /usr/sbin/logsave /usr/sbin/losetup /usr/sbin/mkboot /usr/sbin/mke2fs /usr/sbin/mkfs /usr/sbin/mkfs.cramfs /usr/sbin/mkfs.ext2 /usr/sbin/mkfs.ext3 /usr/sbin/mkfs.minix /usr/sbin/mkfs.ufs /usr/sbin/mklost+found /usr/sbin/mkswap.linux /usr/sbin/move-to /usr/sbin/my-debian /usr/sbin/my-exim /usr/sbin/my-ldso-cfg /usr/sbin/my-lynx-cfg /usr/sbin/newlogs /usr/sbin/newusers /usr/sbin/nfsd /usr/sbin/orphaner /usr/sbin/pam_tally /usr/sbin/purge-deinstalled /usr/sbin/purifica-etc /usr/sbin/pwck /usr/sbin/pwconv /usr/sbin/pwunconv /usr/sbin/rdate /usr/sbin/reboot /usr/sbin/remove-default-ispell /usr/sbin/remove-default-wordlist /usr/sbin/remove-shell /usr/sbin/resize2fs /usr/sbin/rmail /usr/sbin/rmt /usr/sbin/rmt-tar /usr/sbin/rsmtp /usr/sbin/runq /usr/sbin/safe_finger /usr/sbin/select-default-ispell /usr/sbin/select-default-wordlist /usr/sbin/sendmail /usr/sbin/sfdisk /usr/sbin/shadowconfig /usr/sbin/smartlist-hard2sym /usr/sbin/sshd /usr/sbin/start-stop-daemon /usr/sbin/stati.ufs /usr/sbin/swapoff /usr/sbin/swapon /usr/sbin/syslog-facility /usr/sbin/syslogd /usr/sbin/syslogd-listfiles /usr/sbin/t /usr/sbin/tcpd /usr/sbin/tcpdchk /usr/sbin/tcpdmatch /usr/sbin/texconfig /usr/sbin/try-from /usr/sbin/tune2fs /usr/sbin/tzconfig /usr/sbin/unix_chkpwd /usr/sbin/update-alternatives /usr/sbin/update-catalog /usr/sbin/update-default-aspell /usr/sbin/update-default-ispell /usr/sbin/update-default-wordlist /usr/sbin/update-dictcommon-aspell /usr/sbin/update-fmtutil /usr/sbin/update-grub /usr/sbin/update-inetd /usr/sbin/update-ispell-dictionary /usr/sbin/update-mime /usr/sbin/update-openoffice-dicts /usr/sbin/update-passwd /usr/sbin/update-rc.d /usr/sbin/update-texmf /usr/sbin/update-updmap /usr/sbin/useradd /usr/sbin/userdel /usr/sbin/usermod /usr/sbin/vigr /usr/sbin/vipw /usr/sbin/zic and /usr/bin/0 /usr/bin/411toppm /usr/bin/822-date /usr/bin/GET /usr/bin/HEAD /usr/bin/MakeTeXPK /usr/bin/POST /usr/bin/X11 /usr/bin/[ /usr/bin/a2p /usr/bin/access /usr/bin/aclocal /usr/bin/aclocal-1.4 /usr/bin/aclocal-1.6 /usr/bin/aclocal-1.7 /usr/bin/addauth /usr/bin/addftinfo /usr/bin/addr2line /usr/bin/afm2tfm /usr/bin/afmtodit /usr/bin/allcm /usr/bin/allec /usr/bin/allneeded /usr/bin/amstex /usr/bin/anytopnm /usr/bin/apropos /usr/bin/apt-cache /usr/bin/apt-cdrom /usr/bin/apt-config /usr/bin/apt-extracttemplates /usr/bin/apt-ftparchive /usr/bin/apt-get /usr/bin/apt-sortpkgs /usr/bin/ar /usr/bin/arch /usr/bin/as /usr/bin/asciitopgm /usr/bin/atktopbm /usr/bin/audiofile-config /usr/bin/autoconf /usr/bin/autoconf-wrapper /usr/bin/autoconf2.13 /usr/bin/autoconf2.50 /usr/bin/autoheader /usr/bin/autoheader2.13 /usr/bin/autoheader2.50 /usr/bin/autom4te /usr/bin/automake /usr/bin/automake-1.4 /usr/bin/automake-1.6 /usr/bin/automake-1.7 /usr/bin/autopoint /usr/bin/autoreconf /usr/bin/autoreconf2.13 /usr/bin/autoreconf2.50 /usr/bin/autoscan /usr/bin/autoscan2.13 /usr/bin/autoupdate /usr/bin/autoupdate2.13 /usr/bin/awk /usr/bin/b2m /usr/bin/b2m.emacs21 /usr/bin/basename /usr/bin/bash /usr/bin/bashbug /usr/bin/bc /usr/bin/bdftops /usr/bin/bibtex /usr/bin/bioradtopgm /usr/bin/bison /usr/bin/bison-1.35 /usr/bin/bison-1.35.yacc /usr/bin/bison.yacc /usr/bin/bmptopnm /usr/bin/bmptoppm /usr/bin/boot /usr/bin/borra-disquete /usr/bin/borra-enlaces /usr/bin/brushtopbm /usr/bin/bsd-csh /usr/bin/bsd-write /usr/bin/bts /usr/bin/buildhash /usr/bin/bunzip2 /usr/bin/byacc /usr/bin/bzcat /usr/bin/bzcmp /usr/bin/bzdiff /usr/bin/bzegrep /usr/bin/bzfgrep /usr/bin/bzgrep /usr/bin/bzip2 /usr/bin/bzip2recover /usr/bin/bzless /usr/bin/bzmore /usr/bin/c++ /usr/bin/c++filt /usr/bin/c2ph /usr/bin/c89 /usr/bin/c99 /usr/bin/cal /usr/bin/calendar /usr/bin/captoinfo /usr/bin/cat /usr/bin/catchsegv /usr/bin/catman /usr/bin/cc /usr/bin/chage /usr/bin/chattr /usr/bin/checkbash /usr/bin/checkbashisms /usr/bin/chfn /usr/bin/chgrp /usr/bin/chkdupexe /usr/bin/chmod /usr/bin/chown /usr/bin/chsh /usr/bin/cksum /usr/bin/clear /usr/bin/cmp /usr/bin/cmuwmtopbm /usr/bin/col /usr/bin/colcrt /usr/bin/collateindex.pl /usr/bin/colrm /usr/bin/column /usr/bin/comm /usr/bin/compile_et /usr/bin/compose /usr/bin/configurewrapper /usr/bin/console /usr/bin/cp /usr/bin/cpan /usr/bin/cpio /usr/bin/cpp /usr/bin/cpp-3.2 /usr/bin/cpp-3.3 /usr/bin/crontab /usr/bin/csh /usr/bin/csplit /usr/bin/ctags /usr/bin/ctags.emacs21 /usr/bin/ctangle /usr/bin/cut /usr/bin/cvs-debc /usr/bin/cvs-debi /usr/bin/cvs-debrelease /usr/bin/cvs-debuild /usr/bin/cweave /usr/bin/date /usr/bin/db2dvi /usr/bin/db2html /usr/bin/db2pdf /usr/bin/db2ps /usr/bin/db2rtf /usr/bin/db_archive /usr/bin/db_checkpoint /usr/bin/db_deadlock /usr/bin/db_dump /usr/bin/db_dump185 /usr/bin/db_load /usr/bin/db_printlog /usr/bin/db_recover /usr/bin/db_stat /usr/bin/dbs-edit-patch /usr/bin/dc /usr/bin/dch /usr/bin/dd /usr/bin/ddate /usr/bin/deb-make /usr/bin/debc /usr/bin/debchange /usr/bin/debclean /usr/bin/debconf /usr/bin/debconf-communicate /usr/bin/debconf-copydb /usr/bin/debconf-get-selections /usr/bin/debconf-getlang /usr/bin/debconf-gettextize /usr/bin/debconf-loadtemplate /usr/bin/debconf-mergetemplate /usr/bin/debconf-set-selections /usr/bin/debconf-show /usr/bin/debconf-updatepo /usr/bin/debconf2po-update /usr/bin/debconf2pot /usr/bin/debdiff /usr/bin/debi /usr/bin/debiandoc2dvi /usr/bin/debiandoc2html /usr/bin/debiandoc2info /usr/bin/debiandoc2latex /usr/bin/debiandoc2latexdvi /usr/bin/debiandoc2latexpdf /usr/bin/debiandoc2latexps /usr/bin/debiandoc2pdf /usr/bin/debiandoc2ps /usr/bin/debiandoc2texinfo /usr/bin/debiandoc2text /usr/bin/debiandoc2textov /usr/bin/deborphan /usr/bin/debpkg /usr/bin/debrelease /usr/bin/debrsign /usr/bin/debsign /usr/bin/debstd /usr/bin/debuild /usr/bin/defoma /usr/bin/defoma-app /usr/bin/defoma-font /usr/bin/defoma-hints /usr/bin/defoma-id /usr/bin/defoma-reconfigure /usr/bin/defoma-subst /usr/bin/defoma-user /usr/bin/desmonta /usr/bin/devprobe /usr/bin/df /usr/bin/dh_builddeb /usr/bin/dh_buildinfo /usr/bin/dh_clean /usr/bin/dh_compress /usr/bin/dh_fixperms /usr/bin/dh_gconf /usr/bin/dh_gencontrol /usr/bin/dh_install /usr/bin/dh_installcatalogs /usr/bin/dh_installchangelogs /usr/bin/dh_installcron /usr/bin/dh_installdeb /usr/bin/dh_installdebconf /usr/bin/dh_installdefoma /usr/bin/dh_installdirs /usr/bin/dh_installdocs /usr/bin/dh_installemacsen /usr/bin/dh_installexamples /usr/bin/dh_installinfo /usr/bin/dh_installinit /usr/bin/dh_installlogcheck /usr/bin/dh_installlogrotate /usr/bin/dh_installman /usr/bin/dh_installmanpages /usr/bin/dh_installmenu /usr/bin/dh_installmime /usr/bin/dh_installmodules /usr/bin/dh_installpam /usr/bin/dh_installppp /usr/bin/dh_installwm /usr/bin/dh_installxfonts /usr/bin/dh_link /usr/bin/dh_listpackages /usr/bin/dh_makeshlibs /usr/bin/dh_md5sums /usr/bin/dh_movefiles /usr/bin/dh_perl /usr/bin/dh_python /usr/bin/dh_scrollkeeper /usr/bin/dh_shlibdeps /usr/bin/dh_strip /usr/bin/dh_suidregister /usr/bin/dh_testdir /usr/bin/dh_testroot /usr/bin/dh_testversion /usr/bin/dh_undocumented /usr/bin/dh_usrlocal /usr/bin/dialog /usr/bin/diff /usr/bin/diff3 /usr/bin/dir /usr/bin/dircolors /usr/bin/dirname /usr/bin/dmp /usr/bin/dns-helper /usr/bin/dnsdomainname /usr/bin/docbook-to-man /usr/bin/docbook2dvi /usr/bin/docbook2html /usr/bin/docbook2man /usr/bin/docbook2pdf /usr/bin/docbook2ps /usr/bin/docbook2rtf /usr/bin/docbook2tex /usr/bin/docbook2texi /usr/bin/docbook2txt /usr/bin/dot-old-backup /usr/bin/dotextwrap /usr/bin/dotlockfile /usr/bin/dpatch /usr/bin/dpatch-convert-diffgz /usr/bin/dpatch-edit-patch /usr/bin/dpatch-list-patch /usr/bin/dpkg /usr/bin/dpkg-architecture /usr/bin/dpkg-buildpackage /usr/bin/dpkg-checkbuilddeps /usr/bin/dpkg-deb /usr/bin/dpkg-depcheck /usr/bin/dpkg-distaddfile /usr/bin/dpkg-genbuilddeps /usr/bin/dpkg-genchanges /usr/bin/dpkg-gencontrol /usr/bin/dpkg-name /usr/bin/dpkg-parsechangelog /usr/bin/dpkg-query /usr/bin/dpkg-scanpackages /usr/bin/dpkg-scansources /usr/bin/dpkg-shlibdeps /usr/bin/dpkg-source /usr/bin/dpkg-split /usr/bin/dprofpp /usr/bin/dscverify /usr/bin/dselect /usr/bin/du /usr/bin/dvi2fax /usr/bin/dvicopy /usr/bin/dvihp /usr/bin/dvilj /usr/bin/dvilj2p /usr/bin/dvilj4 /usr/bin/dvilj4l /usr/bin/dvilj6 /usr/bin/dvipdf /usr/bin/dvipdfm /usr/bin/dvipdft /usr/bin/dvips /usr/bin/dvired /usr/bin/dvitomp /usr/bin/dvitype /usr/bin/e2pall /usr/bin/ebb /usr/bin/ebrowse /usr/bin/ebrowse.emacs21 /usr/bin/echo /usr/bin/ed /usr/bin/edit /usr/bin/editor /usr/bin/egrep /usr/bin/einitex /usr/bin/elatex /usr/bin/emacs /usr/bin/emacs-21.2 /usr/bin/emacs21 /usr/bin/emacsclient /usr/bin/emacsclient.emacs21 /usr/bin/enc2xs /usr/bin/env /usr/bin/envsubst /usr/bin/eps2eps /usr/bin/epstopdf /usr/bin/eqn /usr/bin/eqn2graph /usr/bin/esd-config /usr/bin/etags /usr/bin/etags.emacs21 /usr/bin/etex /usr/bin/evirtex /usr/bin/excluye /usr/bin/exigrep /usr/bin/expand /usr/bin/expect /usr/bin/expiry /usr/bin/expr /usr/bin/eyuvtoppm /usr/bin/f77 /usr/bin/factor /usr/bin/fakeauth /usr/bin/fakeroot /usr/bin/false /usr/bin/fc-cache /usr/bin/fc-list /usr/bin/fdf2tan /usr/bin/fgrep /usr/bin/fiascotopnm /usr/bin/ficheros-regulares /usr/bin/file /usr/bin/find /usr/bin/find2perl /usr/bin/findaffix /usr/bin/fitstopnm /usr/bin/flea /usr/bin/flex /usr/bin/fmt /usr/bin/fmtutil /usr/bin/fold /usr/bin/font2c /usr/bin/fontexport /usr/bin/fontimport /usr/bin/fontinst /usr/bin/forks /usr/bin/formatea-disquete /usr/bin/freetype-config /usr/bin/from /usr/bin/fstests /usr/bin/fstopgm /usr/bin/fsysopts /usr/bin/ftp /usr/bin/ftpcp /usr/bin/ftpdir /usr/bin/g++ /usr/bin/g++-3.2 /usr/bin/g++-3.3 /usr/bin/g3topbm /usr/bin/g77 /usr/bin/g77-3.3 /usr/bin/gawk /usr/bin/gcc /usr/bin/gcc-3.2 /usr/bin/gcc-3.3 /usr/bin/gccbug /usr/bin/gccbug-3.2 /usr/bin/gccbug-3.3 /usr/bin/gconfigger /usr/bin/gcore /usr/bin/gcov /usr/bin/gcov-3.2 /usr/bin/gcov-3.3 /usr/bin/gdk-pixbuf-config /usr/bin/gemtopbm /usr/bin/gemtopnm /usr/bin/gencat /usr/bin/gensgmlenv /usr/bin/geqn /usr/bin/getconf /usr/bin/getent /usr/bin/getopt /usr/bin/gettext /usr/bin/gettext.sh /usr/bin/gettextize /usr/bin/gftodvi /usr/bin/gftopk /usr/bin/gftype /usr/bin/giftopnm /usr/bin/glib-config /usr/bin/glib-genmarshal /usr/bin/glib-gettextize /usr/bin/glib-mkenums /usr/bin/glibcbug /usr/bin/gnome-bug /usr/bin/gnome-doc /usr/bin/gnome-dump-metadata /usr/bin/gnome-gen-mimedb /usr/bin/gnome-mkstub /usr/bin/gnome-moz-remote /usr/bin/gnome-name-service /usr/bin/gnome_segv /usr/bin/goad-browser /usr/bin/gobject-query /usr/bin/gouldtoppm /usr/bin/gpasswd /usr/bin/gperf /usr/bin/gpic /usr/bin/gprof /usr/bin/grep /usr/bin/grep-changelog /usr/bin/grep-changelog.emacs21 /usr/bin/grep-excuses /usr/bin/grn /usr/bin/grodvi /usr/bin/groff /usr/bin/groffer /usr/bin/grog /usr/bin/grolbp /usr/bin/grolj4 /usr/bin/grops /usr/bin/grotty /usr/bin/groups /usr/bin/gs /usr/bin/gs-gnu /usr/bin/gsftopk /usr/bin/gsl-config /usr/bin/gtbl /usr/bin/gtk-config /usr/bin/guile /usr/bin/guile-1.6 /usr/bin/guile-1.6-config /usr/bin/guile-1.6-snarf /usr/bin/guile-1.6-tools /usr/bin/guile-config /usr/bin/guile-snarf /usr/bin/guile-tools /usr/bin/gunzip /usr/bin/gzexe /usr/bin/gzip /usr/bin/h2ph /usr/bin/h2xs /usr/bin/hd /usr/bin/head /usr/bin/help2man /usr/bin/hexdump /usr/bin/hipstopgm /usr/bin/hostid /usr/bin/hostname /usr/bin/hpftodit /usr/bin/html2text /usr/bin/i386-gnu-cpp /usr/bin/i386-gnu-cpp-3.2 /usr/bin/i386-gnu-cpp-3.3 /usr/bin/i386-gnu-g++ /usr/bin/i386-gnu-g++-3.2 /usr/bin/i386-gnu-g++-3.3 /usr/bin/i386-gnu-g77 /usr/bin/i386-gnu-g77-3.3 /usr/bin/i386-gnu-gcc /usr/bin/i386-gnu-gcc-3.2 /usr/bin/i386-gnu-gcc-3.3 /usr/bin/i586-gnu-cpp-3.3 /usr/bin/i586-gnu-g++-3.3 /usr/bin/i586-gnu-g77-3.3 /usr/bin/i586-gnu-gcc-3.3 /usr/bin/icombine /usr/bin/icontopbm /usr/bin/iconv /usr/bin/id /usr/bin/ids /usr/bin/ifconfig /usr/bin/ifnames /usr/bin/ifnames2.13 /usr/bin/igawk /usr/bin/ijoin /usr/bin/ilbmtoppm /usr/bin/imgtoppm /usr/bin/imlib-config /usr/bin/incluye /usr/bin/indent /usr/bin/indxbib /usr/bin/infocmp /usr/bin/infotocap /usr/bin/inimf /usr/bin/inimpost /usr/bin/iniomega /usr/bin/initex /usr/bin/install /usr/bin/installdeb-aspell /usr/bin/installdeb-ispell /usr/bin/installdeb-myspell /usr/bin/installdeb-wordlist /usr/bin/instant /usr/bin/instmodsh /usr/bin/intltool-extract /usr/bin/intltool-merge /usr/bin/intltool-prepare /usr/bin/intltool-update /usr/bin/intltoolize /usr/bin/ipcrm /usr/bin/ipcs /usr/bin/ispell /usr/bin/ispell-wrapper /usr/bin/jade /usr/bin/jadetex /usr/bin/join /usr/bin/jpegtopnm /usr/bin/jw /usr/bin/kill /usr/bin/kpsepath /usr/bin/kpsestat /usr/bin/kpsetool /usr/bin/kpsewhich /usr/bin/kpsexpand /usr/bin/lambda /usr/bin/latex /usr/bin/latex2html /usr/bin/lcf /usr/bin/ld /usr/bin/ldd /usr/bin/leaftoppm /usr/bin/less /usr/bin/lessecho /usr/bin/lessfile /usr/bin/lesskey /usr/bin/lesspipe /usr/bin/lex /usr/bin/lexgrog /usr/bin/libIDL-config /usr/bin/libart-config /usr/bin/libnetcfg /usr/bin/libpng-config /usr/bin/libpng12-config /usr/bin/libtool /usr/bin/libtoolize /usr/bin/libwmf-config /usr/bin/limpia-tmp /usr/bin/line /usr/bin/link /usr/bin/linuxdoc /usr/bin/lispmtopgm /usr/bin/lkbib /usr/bin/ln /usr/bin/loadshlib /usr/bin/locale /usr/bin/localedef /usr/bin/locate /usr/bin/logger /usr/bin/login /usr/bin/loginpr /usr/bin/logname /usr/bin/look /usr/bin/lookbib /usr/bin/lorder /usr/bin/ls /usr/bin/lsattr /usr/bin/lwp-download /usr/bin/lwp-mirror /usr/bin/lwp-request /usr/bin/lwp-rget /usr/bin/lynx /usr/bin/m4 /usr/bin/macptopbm /usr/bin/mag /usr/bin/mail-files /usr/bin/mailq /usr/bin/mailshar /usr/bin/make /usr/bin/makeindex /usr/bin/makeinfo /usr/bin/makempx /usr/bin/makempy /usr/bin/man /usr/bin/mandb /usr/bin/manpath /usr/bin/mawk /usr/bin/mbchk /usr/bin/mcookie /usr/bin/md5sum /usr/bin/md5sum.textutils /usr/bin/mdatopbm /usr/bin/mergechanges /usr/bin/mf /usr/bin/mf-nowin /usr/bin/mft /usr/bin/mfw /usr/bin/mgrtopbm /usr/bin/mig /usr/bin/minúscula /usr/bin/mk_cmds /usr/bin/mkbimage /usr/bin/mkdep /usr/bin/mkdir /usr/bin/mkfifo /usr/bin/mkfontdesc /usr/bin/mkindex /usr/bin/mknod /usr/bin/mkocp /usr/bin/mkofm /usr/bin/mktemp /usr/bin/mktexfmt /usr/bin/mktexlsr /usr/bin/mktexmf /usr/bin/mktexpk /usr/bin/mktextfm /usr/bin/mmroff /usr/bin/monta /usr/bin/more /usr/bin/mount /usr/bin/mpost /usr/bin/mpto /usr/bin/mptopdf /usr/bin/msgattrib /usr/bin/msgcat /usr/bin/msgcmp /usr/bin/msgcomm /usr/bin/msgconv /usr/bin/msgen /usr/bin/msgexec /usr/bin/msgfilter /usr/bin/msgfmt /usr/bin/msggrep /usr/bin/msginit /usr/bin/msgmerge /usr/bin/msgport /usr/bin/msgunfmt /usr/bin/msguniq /usr/bin/mt /usr/bin/mt-gnu /usr/bin/mtrace /usr/bin/mtvtoppm /usr/bin/muestra-less /usr/bin/munchlist /usr/bin/mutt /usr/bin/mutt_dotlock /usr/bin/muttbug /usr/bin/mv /usr/bin/mysql_config /usr/bin/namei /usr/bin/nano /usr/bin/nawk /usr/bin/ncal /usr/bin/neotoppm /usr/bin/neqn /usr/bin/new-object /usr/bin/newaliases /usr/bin/newer /usr/bin/ngettext /usr/bin/nice /usr/bin/nl /usr/bin/nm /usr/bin/nohup /usr/bin/nroff /usr/bin/nsgmls /usr/bin/objcopy /usr/bin/objdump /usr/bin/od /usr/bin/odvicopy /usr/bin/odvips /usr/bin/odvitype /usr/bin/ofm2opl /usr/bin/omega /usr/bin/omfonts /usr/bin/opl2ofm /usr/bin/orbit-config /usr/bin/orbit-idl /usr/bin/otangle /usr/bin/otp2ocp /usr/bin/outocp /usr/bin/ovf2ovp /usr/bin/ovp2ovf /usr/bin/oxdvi /usr/bin/oxdvi.bin /usr/bin/oxdvi.real /usr/bin/pager /usr/bin/palmtopnm /usr/bin/pamcut /usr/bin/pamdeinterlace /usr/bin/pamdice /usr/bin/pamfile /usr/bin/pamoil /usr/bin/pamstack /usr/bin/pamstretch /usr/bin/pamstretch-gen /usr/bin/paquetes-instalados /usr/bin/passwd /usr/bin/paste /usr/bin/patch /usr/bin/patgen /usr/bin/pathchk /usr/bin/pbmclean /usr/bin/pbmlife /usr/bin/pbmmake /usr/bin/pbmmask /usr/bin/pbmpage /usr/bin/pbmpscale /usr/bin/pbmreduce /usr/bin/pbmtext /usr/bin/pbmtextps /usr/bin/pbmto10x /usr/bin/pbmtoascii /usr/bin/pbmtoatk /usr/bin/pbmtobbnbg /usr/bin/pbmtocmuwm /usr/bin/pbmtoepsi /usr/bin/pbmtoepson /usr/bin/pbmtog3 /usr/bin/pbmtogem /usr/bin/pbmtogo /usr/bin/pbmtoicon /usr/bin/pbmtolj /usr/bin/pbmtomacp /usr/bin/pbmtomda /usr/bin/pbmtomgr /usr/bin/pbmtonokia /usr/bin/pbmtopgm /usr/bin/pbmtopi3 /usr/bin/pbmtoplot /usr/bin/pbmtoppa /usr/bin/pbmtopsg3 /usr/bin/pbmtoptx /usr/bin/pbmtowbmp /usr/bin/pbmtox10bm /usr/bin/pbmtoxbm /usr/bin/pbmtoybm /usr/bin/pbmtozinc /usr/bin/pbmupc /usr/bin/pcre-config /usr/bin/pcretest /usr/bin/pcxtoppm /usr/bin/pdf2dsc /usr/bin/pdf2ps /usr/bin/pdfeinitex /usr/bin/pdfelatex /usr/bin/pdfetex /usr/bin/pdfevirtex /usr/bin/pdfinitex /usr/bin/pdfjadetex /usr/bin/pdflatex /usr/bin/pdfopt /usr/bin/pdftex /usr/bin/pdftosrc /usr/bin/pdfvirtex /usr/bin/perl /usr/bin/perl5.8.3 /usr/bin/perlbug /usr/bin/perlcc /usr/bin/perldoc /usr/bin/perlivp /usr/bin/pf2afm /usr/bin/pfb2pfa /usr/bin/pfbtops /usr/bin/pgawk /usr/bin/pgmbentley /usr/bin/pgmcrater /usr/bin/pgmedge /usr/bin/pgmenhance /usr/bin/pgmhist /usr/bin/pgmkernel /usr/bin/pgmnoise /usr/bin/pgmnorm /usr/bin/pgmoil /usr/bin/pgmramp /usr/bin/pgmslice /usr/bin/pgmtexture /usr/bin/pgmtofs /usr/bin/pgmtolispm /usr/bin/pgmtopbm /usr/bin/pgmtoppm /usr/bin/pi1toppm /usr/bin/pi3topbm /usr/bin/pic /usr/bin/pic2graph /usr/bin/pico /usr/bin/piconv /usr/bin/ping /usr/bin/pinky /usr/bin/pjtoppm /usr/bin/pk2bm /usr/bin/pkg-config /usr/bin/pktogf /usr/bin/pktype /usr/bin/pl2pm /usr/bin/plotchangelog /usr/bin/pltotf /usr/bin/pmake /usr/bin/pngtopnm /usr/bin/pnmalias /usr/bin/pnmarith /usr/bin/pnmcat /usr/bin/pnmcolormap /usr/bin/pnmcomp /usr/bin/pnmconvol /usr/bin/pnmcrop /usr/bin/pnmcut /usr/bin/pnmdepth /usr/bin/pnmenlarge /usr/bin/pnmfile /usr/bin/pnmflip /usr/bin/pnmgamma /usr/bin/pnmhisteq /usr/bin/pnmhistmap /usr/bin/pnmindex /usr/bin/pnminterp /usr/bin/pnminterp-gen /usr/bin/pnminvert /usr/bin/pnmmargin /usr/bin/pnmmontage /usr/bin/pnmnlfilt /usr/bin/pnmnoraw /usr/bin/pnmnorm /usr/bin/pnmpad /usr/bin/pnmpaste /usr/bin/pnmpsnr /usr/bin/pnmquant /usr/bin/pnmremap /usr/bin/pnmrotate /usr/bin/pnmscale /usr/bin/pnmscalefixed /usr/bin/pnmshear /usr/bin/pnmsmooth /usr/bin/pnmsplit /usr/bin/pnmtile /usr/bin/pnmtoddif /usr/bin/pnmtofiasco /usr/bin/pnmtofits /usr/bin/pnmtojpeg /usr/bin/pnmtopalm /usr/bin/pnmtoplainpnm /usr/bin/pnmtopng /usr/bin/pnmtops /usr/bin/pnmtorast /usr/bin/pnmtorle /usr/bin/pnmtosgi /usr/bin/pnmtosir /usr/bin/pnmtotiff /usr/bin/pnmtotiffcmyk /usr/bin/pnmtoxwd /usr/bin/po2debconf /usr/bin/pod2html /usr/bin/pod2latex /usr/bin/pod2man /usr/bin/pod2text /usr/bin/pod2usage /usr/bin/podchecker /usr/bin/podebconf-display-po /usr/bin/podselect /usr/bin/pooltype /usr/bin/portinfo /usr/bin/post-grohtml /usr/bin/ppm3d /usr/bin/ppmbrighten /usr/bin/ppmchange /usr/bin/ppmcie /usr/bin/ppmcolormask /usr/bin/ppmcolors /usr/bin/ppmdim /usr/bin/ppmdist /usr/bin/ppmdither /usr/bin/ppmfade /usr/bin/ppmflash /usr/bin/ppmforge /usr/bin/ppmhist /usr/bin/ppmlabel /usr/bin/ppmmake /usr/bin/ppmmix /usr/bin/ppmnorm /usr/bin/ppmntsc /usr/bin/ppmpat /usr/bin/ppmquant /usr/bin/ppmquantall /usr/bin/ppmqvga /usr/bin/ppmrainbow /usr/bin/ppmrelief /usr/bin/ppmshadow /usr/bin/ppmshift /usr/bin/ppmspread /usr/bin/ppmtoacad /usr/bin/ppmtobmp /usr/bin/ppmtoeyuv /usr/bin/ppmtoicr /usr/bin/ppmtoilbm /usr/bin/ppmtojpeg /usr/bin/ppmtoleaf /usr/bin/ppmtolj /usr/bin/ppmtomap /usr/bin/ppmtomitsu /usr/bin/ppmtompeg /usr/bin/ppmtoneo /usr/bin/ppmtopcx /usr/bin/ppmtopgm /usr/bin/ppmtopi1 /usr/bin/ppmtopict /usr/bin/ppmtopj /usr/bin/ppmtopuzz /usr/bin/ppmtorgb3 /usr/bin/ppmtosixel /usr/bin/ppmtotga /usr/bin/ppmtouil /usr/bin/ppmtowinicon /usr/bin/ppmtoxpm /usr/bin/ppmtoyuv /usr/bin/ppmtoyuvsplit /usr/bin/ppmtv /usr/bin/pr /usr/bin/pre-grohtml /usr/bin/print /usr/bin/printenv /usr/bin/printf /usr/bin/prove /usr/bin/ps /usr/bin/ps2ascii /usr/bin/ps2epsi /usr/bin/ps2frag /usr/bin/ps2pdf /usr/bin/ps2pdf12 /usr/bin/ps2pdf13 /usr/bin/ps2pdf14 /usr/bin/ps2pdfwr /usr/bin/ps2pk /usr/bin/ps2ps /usr/bin/psed /usr/bin/psidtopgm /usr/bin/pslatex /usr/bin/pstoimg /usr/bin/pstopnm /usr/bin/pstruct /usr/bin/pth-config /usr/bin/ptked /usr/bin/ptksh /usr/bin/ptx /usr/bin/puntolist2nada /usr/bin/pwd /usr/bin/pydoc /usr/bin/pydoc2.1 /usr/bin/pydoc2.3 /usr/bin/pygettext /usr/bin/pygettext2.1 /usr/bin/pygettext2.3 /usr/bin/python /usr/bin/python2.1 /usr/bin/python2.3 /usr/bin/qrttoppm /usr/bin/quita_ /usr/bin/ranlib /usr/bin/rasttopnm /usr/bin/rawtopgm /usr/bin/rawtoppm /usr/bin/rbash /usr/bin/rc-alert /usr/bin/rcp /usr/bin/rcs-checkin /usr/bin/rcs-checkin.emacs21 /usr/bin/readelf /usr/bin/readlink /usr/bin/red /usr/bin/refer /usr/bin/remove-empty-directories /usr/bin/remsync /usr/bin/rename /usr/bin/renice /usr/bin/replay /usr/bin/reset /usr/bin/rev /usr/bin/rgb3toppm /usr/bin/rgrep /usr/bin/rletopnm /usr/bin/rlogin /usr/bin/rm /usr/bin/rmauth /usr/bin/rmdir /usr/bin/rpcgen /usr/bin/rpcinfo /usr/bin/rpctrace /usr/bin/rsh /usr/bin/rtf2rtf /usr/bin/rubibtex /usr/bin/rumakeindex /usr/bin/run-mailcap /usr/bin/run-parts /usr/bin/runtest /usr/bin/s2p /usr/bin/savelog /usr/bin/sbigtopgm /usr/bin/scp /usr/bin/script /usr/bin/scrollkeeper-config /usr/bin/scrollkeeper-extract /usr/bin/scrollkeeper-gen-seriesid /usr/bin/scrollkeeper-get-cl /usr/bin/scrollkeeper-get-content-list /usr/bin/scrollkeeper-get-extended-content-list /usr/bin/scrollkeeper-get-index-from-docpath /usr/bin/scrollkeeper-get-toc-from-docpath /usr/bin/scrollkeeper-get-toc-from-id /usr/bin/scrollkeeper-install /usr/bin/scrollkeeper-preinstall /usr/bin/scrollkeeper-rebuilddb /usr/bin/scrollkeeper-uninstall /usr/bin/scrollkeeper-update /usr/bin/sdiff /usr/bin/sed /usr/bin/see /usr/bin/select-default-iwrap /usr/bin/sensible-browser /usr/bin/sensible-editor /usr/bin/sensible-pager /usr/bin/seq /usr/bin/setauth /usr/bin/setsid /usr/bin/setterm /usr/bin/settrans /usr/bin/sfconvert /usr/bin/sfinfo /usr/bin/sftp /usr/bin/sgitopnm /usr/bin/sgml2html /usr/bin/sgml2info /usr/bin/sgml2latex /usr/bin/sgml2lyx /usr/bin/sgml2rtf /usr/bin/sgml2txt /usr/bin/sgml2xml /usr/bin/sgmlcheck /usr/bin/sgmldiff /usr/bin/sgmlnorm /usr/bin/sgmlpre /usr/bin/sgmlsasp /usr/bin/sgmlspl /usr/bin/sgmltools /usr/bin/sgmlwhich /usr/bin/sh /usr/bin/sha1sum /usr/bin/shar /usr/bin/shd /usr/bin/showtrans /usr/bin/shred /usr/bin/sirtopnm /usr/bin/size /usr/bin/sldtoppm /usr/bin/sleep /usr/bin/slogin /usr/bin/smake /usr/bin/soelim /usr/bin/sort /usr/bin/spam /usr/bin/spctoppm /usr/bin/spent /usr/bin/splain /usr/bin/split /usr/bin/sputoppm /usr/bin/sq /usr/bin/ssh /usr/bin/ssh-add /usr/bin/ssh-agent /usr/bin/ssh-argv0 /usr/bin/ssh-copy-id /usr/bin/ssh-keygen /usr/bin/ssh-keyscan /usr/bin/st4topgm /usr/bin/stat /usr/bin/storecat /usr/bin/storeinfo /usr/bin/storeread /usr/bin/strings /usr/bin/strip /usr/bin/stty /usr/bin/su /usr/bin/sum /usr/bin/sush /usr/bin/symlinks /usr/bin/sync /usr/bin/syncfs /usr/bin/syslog /usr/bin/t1mapper /usr/bin/tac /usr/bin/tack /usr/bin/tail /usr/bin/tangle /usr/bin/tar /usr/bin/tbl /usr/bin/tclsh /usr/bin/tclsh8.0 /usr/bin/tclsh8.3 /usr/bin/tclsh8.4 /usr/bin/tee /usr/bin/tempfile /usr/bin/test /usr/bin/tex /usr/bin/texconfig /usr/bin/texdoc /usr/bin/texdoctk /usr/bin/texexec /usr/bin/texexpand /usr/bin/texfind /usr/bin/texfont /usr/bin/texhash /usr/bin/texi2dvi /usr/bin/texi2html /usr/bin/texi2pdf /usr/bin/texindex /usr/bin/texlinks /usr/bin/texshow /usr/bin/texutil /usr/bin/tfmtodit /usr/bin/tftopl /usr/bin/tftp /usr/bin/tgatoppm /usr/bin/thinkjettopbm /usr/bin/thumbpdf /usr/bin/tic /usr/bin/tie /usr/bin/tifftopnm /usr/bin/timertest /usr/bin/tixindex /usr/bin/tixindex8.1 /usr/bin/tixwish /usr/bin/tixwish8.1 /usr/bin/toe /usr/bin/touch /usr/bin/tput /usr/bin/tr /usr/bin/troff /usr/bin/true /usr/bin/tryaffix /usr/bin/tset /usr/bin/tsort /usr/bin/ttf2afm /usr/bin/tty /usr/bin/tzselect /usr/bin/ucf /usr/bin/ul /usr/bin/uname /usr/bin/uncompress /usr/bin/unexpand /usr/bin/uniq /usr/bin/unlink /usr/bin/unshar /usr/bin/unsq /usr/bin/unsu /usr/bin/updatedb /usr/bin/updmap /usr/bin/uptime /usr/bin/uscan /usr/bin/users /usr/bin/uudecode /usr/bin/uuencode /usr/bin/uuidgen /usr/bin/uupdate /usr/bin/vdir /usr/bin/vftovp /usr/bin/virmf /usr/bin/virmpost /usr/bin/viromega /usr/bin/virtex /usr/bin/vminfo /usr/bin/vmstat /usr/bin/vptovf /usr/bin/w /usr/bin/w3c /usr/bin/w3m /usr/bin/w3m-en /usr/bin/w3m-ja /usr/bin/w3mman /usr/bin/wall /usr/bin/wbmptopbm /usr/bin/wc /usr/bin/weave /usr/bin/webbot /usr/bin/whatis /usr/bin/whereis /usr/bin/which /usr/bin/who /usr/bin/whoami /usr/bin/whois /usr/bin/widget /usr/bin/winicontoppm /usr/bin/wish /usr/bin/wish8.4 /usr/bin/wnpp-alert /usr/bin/write /usr/bin/www /usr/bin/www-browser /usr/bin/x-terminal-emulator /usr/bin/xargs /usr/bin/xbmtopbm /usr/bin/xdvi /usr/bin/xdvi.bin /usr/bin/xdvi.real /usr/bin/xdvizilla /usr/bin/xgettext /usr/bin/ximtoppm /usr/bin/xml-config /usr/bin/xml-i18n-toolize /usr/bin/xml2-config /usr/bin/xpmtoppm /usr/bin/xsubpp /usr/bin/xvminitoppm /usr/bin/xwdtopnm /usr/bin/yacc /usr/bin/yada /usr/bin/ybmtopbm /usr/bin/yes /usr/bin/yuvsplittoppm /usr/bin/yuvtoppm /usr/bin/zcat /usr/bin/zcmp /usr/bin/zdiff /usr/bin/zdump /usr/bin/zegrep /usr/bin/zeisstopnm /usr/bin/zfgrep /usr/bin/zforce /usr/bin/zgrep /usr/bin/zile /usr/bin/zless /usr/bin/zmore /usr/bin/znew /usr/bin/zsoelim executables as owned by `bin', this account will not flag a warning.

Linux (notably RedHat) operating environments violate this convention with printer (lp*) and rpm programs among others. Changing ownership in this case may be problematic.












Code [path003i]

No PATH variable could be extracted from the indicated file. This either indicates that the PATH is not set in the file, or that the file is too complex to be able to extract it.












Code [path004w]

The PATH variable from the indicated initialization file for `root' puts `.' (dot) in the PATH. Having dot in `root's path can allow Trojan horse programs to be unknowingly executed by root.

References: curry/33-34 garfinkel/151-153












Code [path005w]

The PATH variable from the indicated user and initialization file contains the `.' (dot) directory, but it is not the last component. This can cause Trojan horse programs to be executed. It is recommended that `.' not be in the PATH (especially for `root'), but if it is included, it should be the last directory listed in the PATH variable.

References: curry/33-34 garfinkel/151-153












Code [path006w]

The indicated directory from a user's PATH variable is writable. This can allow commands in this directory to be replaced with Trojan horse programs. Note that this can be reported even if the directory itself does not have group or world write permissions. This message is generated if any directory component of the pathname is writable (the directory itself can be replaced with a new, writable one if a directory higher up is writable).

References: curry/33-34 garfinkel/151-153












Code [path007w]

The indicated directory is in `root's PATH, but is not owned by 'root'. This can allow Trojan horse programs to be placed into any executables in this directory. The ownership of the directory should be changed to `root'.












Code [path008i]

The indicated setuid program is in root's PATH, but is not owned by root. Since it is setuid to a user other than root, there usually is no solution for this. You should be aware of these though, as they can allow Trojan horse programs or viruses to be planted into these executables and spread by `root'. Often these executables are owned by `bin', `uucp' or other system accounts. If these commands are never used by root, then this is not a problem.












Code [path009w]

An initial setting of the PATH variable should be setup in the default locations for shell login programs (/etc/profile, /etc/csh.login, etc.).