Home page logo
/

bugtraq logo Bugtraq mailing list archives

Major security-hole in kerberos rsh, rcp and rlogin.
From: e96_agr () E KTH SE (Artur Grabowski)
Date: Mon, 3 Nov 1997 02:18:49 +0100


There has been discovered a security-hole in kerberized rsh, rcp and rlogin.

Everyone who has setuid-bits set on these applications is adviced to disable
them.

The hole allows any user on the system to gain privilegies of any other user
including root.

The hole has been successfully tested on kth-kerberos, but is suspected to
exist on any other versions of kerberos.

//Artur Grabowski (administrator on stacken.kth.se)



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]