[3482] in bugtraq

home help back first fref pref prev next nref lref last post

Re: ftpd bug? Was: bin/1805: Bug in ftpd

daemon@ATHENA.MIT.EDU (Doug Williams)
Wed Oct 16 21:38:56 1996

Date: 	Wed, 16 Oct 1996 14:15:26 -0400
Reply-To: Doug Williams <dougw@NCCCS.CC.NC.US>
From: Doug Williams <dougw@NCCCS.CC.NC.US>
X-To:         Micah Brandon <brandon@eniac.vv.com>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In-Reply-To:  <199610160722.DAA00169@eniac.vv.com>

> > SunOS 5.5:
> >
> > logon via ftp with your regular user/password,
> > ftp> cd /tmp
> > ftp> user root wrongpasswd
> > ftp> quote pasv
> >
> > voila, root password in world readable core dump under /tmp
> >
>         I was able to create this core file under Solaris 2.4 as well...and
> if I took the time to create a symbolic link before doing the above
> procedure, I was able to create files anywhere on the system :(
>

I got the same on Solaris 2.4.  Being swamped right now I thought I might
create an empty "core" in /tmp and permissions to 000.  When doing the ftp
exploit it fills/replaces the core file, but leaves the permissions
intact.   ...Maybe this soft patch will hold for a bit?

home help back first fref pref prev next nref lref last post