RE: [Bulk] Re: Linux X86 fileutils-4x local root exploit
Arjan van de Ven <[email protected]>
| Newsgroups | gmane.linux.redhat.release.taroon.general |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 2006-07-04 at 14:23 +0100, Sharpe, Sam J wrote: > I wouldn't run it if I were you. > > I'm not an exploit guru, but I just ran it as me on a play server > (RHEL3) and ended up with a root shell prompt. it's not an actual root shell, it's a shell who's getuid() function call is overloaded to return 0 always, so that the /bin/sh process thinks it's called as root. That's not the same as BEING root. > Then the system hung... yeah because the program has a forkbomb in it to prevent you from doing much so that you on first face value can't find out that the "root" shell isn't actually running with root privileges. It's a nice haux, I'll give the author that ;-) -- Taroon-list mailing list [email protected] https://www.redhat.com/mailman/listinfo/taroon-list