mailing list archives
Re: PuTTY private key passphrase stealing attack
From: paul.szabo () sydney edu au
Date: Thu, 3 Jun 2010 05:58:48 +1000
... someone with access to a single account could use this to
gain the password for that account, and hence possibly sudo access.
Oh yes, someone with access to an account has... access to that.
If he wanted sudo, then just have a fake sudo: one that traps the
password and runs the real sudo after; or one that runs the real
sudo but prepending the "bad" command.
Paul Szabo psz () maths usyd edu au http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics University of Sydney Australia
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/