Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Owning privileged processes under UnixWare

Re: Owning privileged processes under UnixWare

From: Elias Levy <aleph1_at_SECURITYFOCUS.COM>
Date: Mon, 6 Dec 1999 19:04:27 -0800

It seems the basic problem is that SCO has implemented privileges in
UnixWare without thinking of possible interaction with other subsystems.
They should have placed the same restriction on application running with
privileges as those placed on applications running suid or sgid. I am
surprised no one before noticed this. Its a hole you could drive a truck
through. The engineers that coded the privilege system (a security subsystem!)
should get a good ass chewing or get fired.

--
Elias Levy
Security Focus
http://www.securityfocus.com/
Received on Dec 07 1999
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos