Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 25 Jun 1996 01:18:45 +0100
From:      "Gary Palmer" <gpalmer@FreeBSD.ORG>
To:        -Vince- <vince@mercury.gaianet.net>
Cc:        hackers@FreeBSD.ORG, security@FreeBSD.ORG
Subject:   Re: I need help on this one - please help me track this guy down! 
Message-ID:  <27780.835661925@palmer.demon.co.uk>
In-Reply-To: Your message of "Mon, 24 Jun 1996 16:54:26 PDT." <Pine.BSF.3.91.960624165238.21697L-100000@mercury.gaianet.net> 

next in thread | previous in thread | raw e-mail | index | archive | help

[ CC: Trimmed ]

> 	Yeah, that's the real question is like if he can transfer the 
> binary from another machine and have it work... other people can do the 
> same thing and gain access to FreeBSD boxes as root as long as they have 
> a account on that machine...

Sort of. You need root access in the first place to create a suid root
shell... It could be an old exploit that is now closed (like the
mount_union loophole)...

Gary
--
Gary Palmer                                          FreeBSD Core Team Member
FreeBSD: Turning PC's into workstations. See http://www.FreeBSD.ORG/ for info



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?27780.835661925>