[3480] in bugtraq
Re: ftpd bug? Was: bin/1805: Bug in ftpd
daemon@ATHENA.MIT.EDU (Doug Williams)
Wed Oct 16 21:00:58 1996
Date: Wed, 16 Oct 1996 14:22:06 -0400
Reply-To: Doug Williams <dougw@ncccs.cc.nc.us>
From: Doug Williams <dougw@ncccs.cc.nc.us>
X-To: Micah Brandon <brandon@eniac.vv.com>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In-Reply-To: <Pine.SCO.3.95.961016141119.5644A-100000@sco.ncccs.cc.nc.us>
>
> > > SunOS 5.5:
> > >
> > > logon via ftp with your regular user/password,
> > > ftp> cd /tmp
> > > ftp> user root wrongpasswd
> > > ftp> quote pasv
> > >
> > > voila, root password in world readable core dump under /tmp
> > >
> > I was able to create this core file under Solaris 2.4 as well...and
> > if I took the time to create a symbolic link before doing the above
> > procedure, I was able to create files anywhere on the system :(
> >
>
> I got the same on Solaris 2.4. Being swamped right now I thought I might
> create an empty "core" in /tmp and permissions to 000. When doing the ftp
> exploit it fills/replaces the core file, but leaves the permissions
> intact. ...Maybe this soft patch will hold for a bit?
>
*POOOWWWWW* (delusional patch blow)
Ummmmm... never mind, I'm a dolt. I was able to surf around until I found
another 777 directory and Voila!