Bugtraq mailing list archives

Re: Redhat man exploit


From: jbrahy () hades lb devry edu (John Brahy)
Date: Fri, 9 Oct 1998 12:09:07 -0700


Redhat 5.0
[jbrahy@hades jbrahy]$ uname -a
Linux hades 2.0.31 #1 Sun Nov 9 21:45:23 EST 1997 i586 unknown
[jbrahy@hades jbrahy]$ ./MX ls
Using address: 0xbffffd90
bash$ id
uid=648(jbrahy) gid=653(jbrahy) egid=15(man) groups=653(jbrahy)
bash$ man -version
man, version 1.4j

bash$
-----
Redhat 5.1 isn;t
[jbrahy@jed jbrahy]$ uname -a
Linux jed 2.0.35 #1 Tue Jul 14 23:56:39 EDT 1998 i586 unknown
[jbrahy@jed jbrahy]$
[jbrahy@jed jbrahy]$ ./MX ls 2>/dev/null
Using address: 0xbffffda0
[jbrahy@jed jbrahy]$ id
uid=420(jbrahy) gid=1134(NNL) groups=1134(NNL)
[jbrahy@jed jbrahy]$


-----------

This could be either the kernel or the man version.
but probably the man version IMHO.

John



Current thread: