Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: RedHat 6.1 /and others/ PAM

Re: RedHat 6.1 /and others/ PAM

From: Simple Nomad <thegnome_at_NMRC.ORG>
Date: Tue, 1 Feb 2000 17:01:33 -0600

Maybe I should restate. The sploit as it stands didn't work, and even
using expect, pty, etc didn't work. Still showing up in syslog on RH 6.1,
can someone else confirm/deny?

- Simple Nomad - No rest for the Wicca'd -
- thegnome_at_nmrc.org - www.nmrc.org -
- thegnome_at_razor.bindview.com - www.bindview.com -

On Tue, 1 Feb 2000, Pavel Kankovsky wrote:

> On Mon, 31 Jan 2000, Simple Nomad wrote:
>
> > Trying to "echo PASSWORD | su ACCOUNT" will elicit a response of
> > "standard in must be a tty..." therefore the sploit would stop on the
> > first word in the list as if it was the correct password. Therefore I fail
> > to see the exact sploit here. I tried this on a stock RH 6.1 machine.
>
> Use a pseudoterminal. Expect is your friend.
>
> --Pavel Kankovsky aka Peak [ Boycott Microsoft--http://www.vcnet.com/bms ]
> "Resistance is futile. Open your source code and prepare for assimilation."
>
Received on Feb 02 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos