[39916] in bugtraq
Re: Re: Local privilege escalation using runasp V3.5.1
daemon@ATHENA.MIT.EDU (securityfocus.5.stele@spamgourmet.)
Tue Jul 26 15:49:29 2005
Date: 26 Jul 2005 16:37:49 -0000
Message-ID: <20050726163749.30331.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: securityfocus.5.stele@spamgourmet.com
To: bugtraq@securityfocus.com
Correct! -> All critical files should not be modifyalbe by an normal user!
Users should not be able to modify the program files directory too.