Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: Possible SunOS 5.5.1 sulogin vulnerability

Re: Possible SunOS 5.5.1 sulogin vulnerability

From: Michael Douglass <mikedoug_at_texas.net>
Date: Fri, 15 Nov 1996 18:26:23 -0600

On Wed, 13 Nov 1996, Jason R. Mastaler wrote:

> Possible hole in sulogin here? Under Solaris 2.5.1 (sparc & x86),
> executing /sbin/sulogin from an unprivileged user account dumps you
> into what appears to be single-user mode with an ugly warning message
> without prompting for the root password. You don't find this with
> earlier versions of Solaris (2.5 and lower).

sulogin is *not* suid root... It is run as root when the system comes up
in single user mode. The reason you get the ERROR NO root PASSWD is
because it cannot read /etc/shadow as the unprived user. If you were
to do id -a you would see that you are still the same unpriveledged user.

No security hole here.

Michael Douglass
Texas Networking, Inc.

 "Love does not consist in gazing at each other but in looking together in
  the same direction."
      Antoine de Saint-Exupery: Wind, Sand, and Stars, ch. 8 (1939).
Received on Nov 15 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos