logoalt Hacker News

Backslasher • today at 1:56 PM • 4 replies • view on HN

Afaik it's habit to give system paths precedence so a malicious script can't shadow e.g. sudo and steal your password, escalating a local file write into root


Replies

toast0 • today at 2:10 PM

Otoh, if you don't put your local path first, you can't override system binaries that you want to override.

Also, if something can write into your path, it can probably write to your shell config and/or the environment variables.

➕ show 2 replies
marcosdumay • today at 3:53 PM

That's important only for the people that add relative names (like '.') to their path.

Most people know better.

paulddraper • today at 2:06 PM

AFAIK it's habit to allow your scripts to override system ones, so you can customize behavior.

I've always seen home dir, homebrew, etc prepending to PATH.

gjvc • today at 3:38 PM

by that time it's too late and should have been prevented appearing on the host much earlier