Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: Re: [SuSE 9.0] possible symlink attacks in some scripts

Re: [SuSE 9.0] possible symlink attacks in some scripts

From: Thomas Biege <thomas_at_suse.de>
Date: Thu, 22 Jan 2004 09:08:07 +0100 (CET)

>greetings,

Hello.

>i have done a litte reseach on a SuSE linux 9.0 box
>for possible symlink attacks. i have checked nearly
>every script i could found on the system. i havent
>found much and nothing very special.

Good.

>i dont have a
>clue if the following scripts are somewhere on the
>system executed but maybe someone useses them in a
>script or something like that.

We will fix the bugs you found, but it's always nicer
to contact us before you go public with bug-reports.
Just write an eMail to security_at_suse.de and you will
get an answer after a few hours or less.

Bye,
     Thomas

-- 
  Thomas Biege <thomas_at_suse.de>, SUSE LINUX AG, Security Support & Auditing
--
# If you have the "driftnet" program installed, webcollage can display a
# collage of images sniffed off your local ethernet, instead of pulled out
# of search engines: in that way, your screensaver can display the images
# that your co-workers are downloading!
                                          -- xscreensaver source-code
Received on Jan 22 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]