Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: OpenSSH's UseLogin option allows remote access with root privilege.

Re: OpenSSH's UseLogin option allows remote access with root privilege.

From: Markus Friedl <markus.friedl_at_INFORMATIK.UNI-ERLANGEN.DE>
Date: Mon, 12 Jun 2000 11:58:00 +0200

On Sat, Jun 10, 2000 at 02:54:25PM -0700, Phil Stracchino wrote:
> *** session.c.orig Fri May 19 19:49:31 2000
> --- session.c Fri Jun 9 23:45:28 2000

this is a bad patch, the check for (options.use_login && command
!= NULL) should be compiled into sshd even if USE_PAM is defined.
a correct patch is attached.

moreover, i got some complaints from people who ship OpenSSH and
did not get notified in advance. we don't all who ship OpenSSH,
so please tell me at <markus_at_openssh.com> if you want to get notified
in the future.

<HR NOSHADE>
<UL>
<LI>text/plain attachment: 1_
</UL>
Received on Jun 12 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos