Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 27 Jun 1996 11:21:23 -0700 (MST)
From:      Terry Lambert <terry@lambert.org>
To:        mbarkah@hemi.com (Ade Barkah)
Cc:        terry@lambert.org, hackers@freebsd.org
Subject:   Re: I need help on this one - please help me track this guy down!
Message-ID:  <199606271821.LAA05413@phaeton.artisoft.com>
In-Reply-To: <199606270141.TAA25732@hemi.com> from "Ade Barkah" at Jun 26, 96 07:41:58 pm

next in thread | previous in thread | raw e-mail | index | archive | help
> > rcp preserves suid/sgid on the target system.  Now look for a 
> > writeable sticky directory...
> 
> I don't think this is true... even if it were, now the user owns
> a setuid/setgid file, no big deal.

Directory ownership can determine file ownership -- or at least group
ownership.

Easy to build group wheel, bin, or kmem binaries, assuming writable
directories somewhere.

Alternately, of you have mounted via an SVR3 NFS system, you can
"give away" the file or directory to root via chmod.


Where there is a will, there is a way.


					Terry Lambert
					terry@lambert.org
---
Any opinions in this posting are my own and not those of my present
or previous employers.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199606271821.LAA05413>