Full Disclosure mailing list archives

Re: I find a bug


From: Emanuel dos Reis Rodrigues <emanueldosreis () gmail com>
Date: Tue, 18 Jan 2011 09:20:20 -0400

How ?

There is not a bug, it is only work if your sudo configuration is without password to ALL or the strace command. some distributions have this configuration to default user.

You can test or give us more details ?


Emanuel dos Reis Rodrigues
Senior Level Linux Professional (LPIC-3) LPI 302 (Mixed Environment) Specialty
LPI 304 (Virtualization and High Availability) Specialty
C|EH Certified Ethical Hacker
CompTIA Security+ Certified
http://br.linkedin.com/in/emanuelreis
t:@emanueldosreis
emanueldosreis(No*SpAm)gmail.com
Mobile: +55 95 8112-9628








???????? wrote:
hello,
I found a bug,
run [sudo strace su] command can get root privileges without any password.
bill
------------------ Original ------------------
*From: * "Steve Beattie"<sbeattie () ubuntu com>;
*Date: * Thu, Jan 13, 2011 08:01 PM
*To: * "ubuntu-security-announce"<ubuntu-security-announce () lists ubuntu com>; *Cc: * "full-disclosure"<full-disclosure () lists grok org uk>; "bugtraq"<bugtraq () securityfocus com>;
*Subject: * [USN-1042-2] PHP5 regression
--
ubuntu-security-announce mailing list
ubuntu-security-announce () lists ubuntu com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

------------------------------------------------------------------------

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: