Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 24 Jun 1996 22:27:09 +0200
From:      Mark Murray <mark@grumble.grondar.za.@grondar.za>
To:        Veggy Vinny <richardc@CSUA.Berkeley.EDU>
Cc:        Mark Murray <mark@grumble.grondar.za>, Wilko Bulte <wilko@yedi.iaf.nl>, "Jordan K. Hubbard" <jkh@time.cdrom.com>, guido@gvr.win.tue.nl, hackers@freebsd.org, security@freebsd.org, ache@freebsd.org
Subject:   Re: I need help on this one - please help me track this guy down! 
Message-ID:  <199606242027.WAA06360@grumble.grondar.za>

next in thread | raw e-mail | index | archive | help
Veggy Vinny wrote:
> > Take claims like this with a pinch of salt. ;-)
> 
> 	I know but I tried it and it does let me run vipw ;-)
> 
> > What is the program? If we know how it works, we can fix any secuity hole
> > it may be exploiting.
> 
> 	Hmmm, the program is called root, no sources.. it's just a 278k 
> binary...  

With a setuid bit?

Does ktrace(1) give any clues?

What do you get from strings(1)? (Long shot..)

What other exploration have you done?

M
--
Mark Murray
46 Harvey Rd, Claremont, Cape Town 7700, South Africa
+27 21 61-3768 GMT+0200
Finger mark@grondar.za for PGP key



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199606242027.WAA06360>