[comp.unix.xenix] An Editor for SCO Xenix 2.3.2

cat@tygra.UUCP (John Palmer) (03/12/90)

I'm running a computer conferencing system here and am in need of
a version of vi for which the source is available. The problem with
VI as it stands now is that it allows:
    1> shell escapes
    2> the ability to read in text from another file
    3> the ability to write text to a file other than the file with
       which vi was invoked.
    4> the ability to completly switch files.
This is a grave security loophole that I want to eliminate, but I must have
the source code. If there are other editors that are similar to vi, or
even a little more user-friendly, and if the sources are available for
them, then mayby I'll switch. 

Thanks in advance
John Palmer
E-MAIL: jpp%tygra.uucp@sharkey.cc.umich.edu

roy@comcon.UUCP (News Admin) (03/12/90)

In article <90@tygra.UUCP>, cat@tygra.UUCP (John Palmer) writes:
> 
> I'm running a computer conferencing system here and am in need of
> a version of vi for which the source is available. The problem with

I think you'd like Stevie. Version 3.69 was just posted to
comp.sources.misc.

I installed a restricted_user function in my copy, and use it on my bbs.
Under restricted mode, a user may not perform a shell escape, hand off
shell commands, change the name of the current file, edit an alternate
file, or read in a file from other than his home directory. 

T'was easy... the mods took less than an hour.
-- 
_R_o_y _M_. _S_i_l_v_e_r_n_a_i_l  | UUCP: uunet!comcon!roy  |  "Every race must arrive at this
#include <opinions.h>;#define opinions MINE  |   point in its history"
SnailMail: P.O. Box 210856, Anchorage,       |   ........Mr. Slippery
Alaska, 99521-0856, U.S.A., Earth, etc.      |  <Ono-Sendai: the right choice!>

davidc@vlsisj.VLSI.COM (David Chapman) (03/13/90)

In article <90@tygra.UUCP> cat@tygra.UUCP (John Palmer) writes:
>I'm running a computer conferencing system here and am in need of
>a version of vi for which the source is available.

Stevie, which is supposed to be a vi workalike, was just posted to
comp.sources.misc.  I just got it today (3/12) and don't know anything
more about it.  But it may be just what you're looking for.
-- 
		David Chapman

{known world}!decwrl!vlsisj!fndry!davidc
vlsisj!fndry!davidc@decwrl.dec.com