home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!caen!batcomputer!ghost.dsi.unimi.it!cotrozzi
- From: cotrozzi@ghost.dsi.unimi.it (Massimo Cotrozzi)
- Subject: Re: Setuid file
- References: <chupchup.720790116@piggy> <1d9ggiINNsfb@sequoia.ccsd.uts.EDU.AU> <1992Nov5.090120.14723@lut.ac.uk>
- Organization: Computer Science Dep. - Milan University
- Date: Fri, 6 Nov 1992 09:44:21 GMT
- Message-ID: <1992Nov6.094421.21364@ghost.dsi.unimi.it>
- Lines: 20
-
- jon@hill.lut.ac.uk (Jon P. Knight) writes:
-
- >In article <1d9ggiINNsfb@sequoia.ccsd.uts.EDU.AU> mgream@acacia (Matthew Gream) writes:
- >>Robert Earl (chupchup@ferkel.ucsb.edu) wrote:
- >>:
- >>: | Found this on one of our systems. Anyone know if there is any way
- >>: | this could be used to obtain root access?
- >>: | -rwsr-xr-x 1 root 0 Apr 7 1992 file
- >>:
- >>No one yet asked what OS this was, HP-UX doesnt clear the setuid-bit on
- >>an append (at least It didnt in one of its installed versions ive seen),
- >>so appending a shell script to make a setuid shell is a trivial job.
- >>
-
- >But you'd need to be root to write to this file anyway...
-
- But you'd need to be root to CREATE this file anyway...
-
- ( If nobody created it then sorry, machine was cracked .. )
-
- --
- -- Massimo Cotrozzi Computer Science Dept. Milan Italy
- cotrozzi@ghost.dsi.unimi.it +39-2-27201253
- #include <std/disclaimer.h>
-