Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 25 Jun 1996 13:27:02 -0700 (PDT)
From:      -Vince- <>
Cc:, jbhunt <>, Chad Shackley <>
Subject:   Re: Re(2): I need help on this one - please help me track this guy down!
Message-ID:  <>
In-Reply-To: <"811-960625150230-D047*/G=Andrew/S=Gordon/O=NET-TEL Computer Systems Ltd/PRMD=NET-TEL/ADMD=Gold 400/C=GB/"@MHS>

Next in thread | Previous in thread | Raw E-Mail | Index | Archive | Help
On Tue, 25 Jun 1996 wrote:

> > -Vince- stands accused of saying:
> > > 
> > >       Yeah, you have a point but jbhunt was watching the user as he 
> > > hacked root since he brought the file from his own machine.... so that 
> > > wasn't something the admin was tricked into doing..
> But what file transfer mechanism was used?  NFS maybe?
> Certainly a simple NFS mount of an untrusted machine is a dangerous thing to do, since setuids on those files will be obeyed.  Maybe you allow this via an incautious AMD map?
> Personally, I like to mount all NFS filesystems "nosuid" - and likewise for all local systems exported by NFS (I don't normally export / or /usr).  Most users have no business creating setuid programs in their filespace, and such a policy would most likely have prevented this breach even if the setuid binary was created by some other means.

	Probably ftp using a compressed tar or gzipped tar binary...


Want to link to this message? Use this URL: <>