Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Root shell vixie cron exploit
From: raymond () THRIJSWIJK NL (Raymond Dijkxhoorn)
Date: Tue, 7 Sep 1999 12:04:57 +0200


Hi!

  I had assumed that the whole problem with the vixie-cron exploit was
that cron allowed users to invoke sendmail with arbitrary command-line
options *as root*, so dropping SUID status doesn't do any good.
Sendmail doesn't try to protect the root user from themselves.

I tried it on several RedHat 4.x 5.x and 6.x boxes and when they ARE
running sendmail, a lot alsos did qmail, it worked just fine...

Bye,
Raymond.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]