[176] in linux-security and linux-alert archive
DIP suid security problem
daemon@ATHENA.MIT.EDU (Benedikt Stockebrand)
Sat Mar 18 12:03:09 1995
Date: Tue, 14 Mar 1995 01:40:36 +0100
From: Benedikt Stockebrand <benedikt@devnull.ping.de>
To: linux-security@tarsier.cv.nrao.edu
Cc: volkerdi@mhd1.moorhead.msus.edu
I don't know if this is already known but the Slackware 2.1.0
distribution has a security problem with dip (dip-3.3.7i) set suid
root and world executable. Using the -v option shows you the password
used to connect to the remote host.
Ben
-----------------------------------------------------------------------
Benedikt (Ben) Stockebrand (benedikt@devnull.ping.de) Dortmund, Germany
And don't tell me about Benedict Arnold anymore...
-----------------------------------------------------------------------