[1030] in bugtraq
Re: HP-UX Problem...
daemon@ATHENA.MIT.EDU (Andrew Hughes)
Mon Feb 20 18:50:34 1995
From: andrewh@cs.hmc.edu (Andrew Hughes)
To: ajs@vorlon.ajs.com (Aaron Sherman)
Date: Mon, 20 Feb 1995 13:29:32 -0800 (PST)
Cc: ch11mh@surrey.ac.uk, bugtraq@fc.net
In-Reply-To: <199502200942.EAA01941@vorlon.ajs.com> from "Aaron Sherman" at Feb 20, 95 04:42:35 am
>
> Did HP ever fix the diagnostic program that was SUID root, and
> would read any file as a directive file? I found it amusing to
> run this, and have it report "blah is unrecognized" for each line,
> where "blah" is the contents of each line, one at a time, of any
> system file, regardless of ownership and mode ;-) I told the HP
> rep that came in to do some performance tuning for us, but I
> don't know what he did or did not do about it.
>
Assuming you're talking about sysdiag with the "usefile" command, it seems
to have been fixed as of DUI Version A.02.24, if not before (I'm just going
by the version info it prints out when run). You get a SECURITY VIOLATION
error message or some such if you try to look at afile you shouldn't. :-)
AndrewH