Bugtraq mailing list archives
Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm]
From: henson () intranet csupomona edu (Paul B. Henson)
Date: Thu, 5 Dec 1996 14:32:59 -0800
You could create the link (to .rhosts in the example) using the <gibberish characters> file name created by chkperm and accomplish the same result.
Tried that. It just created a file with an additional gibberish character in it instead of following the link :)... Also, the gibberish file, while owned by bin, has perms 644, not 666, on my system. -- Paul Henson | System Administrator | Cal Poly Pomona | (909) 869-3781 pbhenson () csupomona edu | finger henson () brick dce csupomona edu for PGP key
Current thread:
- Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm] Terrell Thacker (Dec 05)
- Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm] Paul B. Henson (Dec 05)
- SGI Security Advisory 19961201-01-PX - Desktop searchbook Program SGI Security Coordinator (Dec 05)
- suid_exec problem clarification Yuri Volobuev (Dec 05)
- Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm] Nikolai Matyushenko (Dec 06)
- Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm] Paul B. Henson (Dec 06)
- New INN security problems Chris Timmons (Dec 06)
- suid_exec Javier Romeu (Dec 06)
- <Possible follow-ups>
- Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm] Kevin L Prigge (Dec 05)
- Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm] Paul Ashton (Dec 06)
- Re: Solaris 2.x Vulnerability [/usr/vmsys/bin/chkperm] Casper Dik (Dec 06)
