Bugtraq mailing list archives

Re: Mandrake 7.0: /usr/bin/cdrecord gid=80 (strike #2)


From: dankamin () CISCO COM (Dan Kaminsky)
Date: Mon, 29 May 2000 20:41:13 -0700


U may say gid=80 (cdwriter) is useless but anyways here is the xploit

If you've got cdwriter access, and they have a SCSI hard drive, then you
should theoretically have read/write access to their raw partitions.  I'm
sure I don't need to go into depth on what that should mean.

Yours Truly,

    Dan Kaminsky


Current thread: