Full Disclosure mailing list archives
Re: Back To The Future: Unix Wildcards Gone Wild
From: Nico Le Moin <nicolemoin01 () gmail com>
Date: Sun, 29 Jun 2014 10:12:20 +0200
This happens on f5 appliances: the tomcat user can upload files to /shared/images , then this root process periodically scans the directory looking for firmware. Shell expansion causes privesc here :p Also, there are no csrf tokens in the firmware upload form. vdbs can go wild now :p On Sat, Jun 28, 2014 at 11:29 PM, Daniel Miller <bonsaiviking () gmail com> wrote:
On Sat, Jun 28, 2014 at 5:06 AM, fulldisclosure < fulldisclosure () evolution-hosting eu> wrote:to be honest, bash shouldn't expand * to "file1 file2 file3 -rf..." it should do it to " 'file1' 'file2' 'file3' '\-rf'..." instead, with all meta chars escaped properly.But this breaks my directory metadata scheme: important directories contain a file named "-i", unimportant ones have "-f". _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
_______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/
Current thread:
- Back To The Future: Unix Wildcards Gone Wild defensecode (Jun 26)
- Re: Back To The Future: Unix Wildcards Gone Wild Michal Zalewski (Jun 26)
- Re: Back To The Future: Unix Wildcards Gone Wild Julius Kivimäki (Jun 27)
- Re: Back To The Future: Unix Wildcards Gone Wild fulldisclosure (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild Daniel Miller (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild Nico Le Moin (Jun 29)
- Re: Back To The Future: Unix Wildcards Gone Wild fulldisclosure (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild gremlin (Jun 27)
- Re: Back To The Future: Unix Wildcards Gone Wild Nick Lindridge (Jun 27)
- Re: Back To The Future: Unix Wildcards Gone Wild steel-wing (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild Cley Faye (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild * (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild steel-wing (Jun 28)
- Re: Back To The Future: Unix Wildcards Gone Wild Ivan Delalande (Jun 27)
- Re: Back To The Future: Unix Wildcards Gone Wild Michal Zalewski (Jun 27)
- Re: Back To The Future: Unix Wildcards Gone Wild Peter Stamfest (Jun 29)