Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: Re: Linux kernel source archive vulnerable

Re: Re: Linux kernel source archive vulnerable

From: Jurjen Oskam <jurjen_at_stupendous.org>
Date: Fri, 8 Sep 2006 20:30:24 +0200

On Fri, Sep 08, 2006 at 08:17:05PM +0200, Hadmut Danisch wrote:

> It may sound funny to consider tar as the wrong tool, but it is.

Don't. Untar. Archives. As. Root.

It's that simple.

Or are you also going to complain about the fact that there are tar
versions out there that don't strip a leading / from the archive?
Much fun can be had when you carelessly extract as root, then.

-- 
Jurjen Oskam
Savage's Law of Expediency:
        You want it bad, you'll get it bad.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Sep 08 2006
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos