Full Disclosure mailing list archives

OS X Local Root: Silly SUID Helper in Tunnel Blick


From: "Jason A. Donenfeld" <Jason () zx2c4 com>
Date: Sat, 11 Aug 2012 09:19:36 +0200

Tunnel Blick is a fun punching bag. Lots of possible exploits.

Lots of vulnerable SUID code:
http://code.google.com/p/tunnelblick/source/search?q=openvpnstart.m&origq=openvpnstart.m&btnG=Search+Trunk

One such exploit: http://git.zx2c4.com/Pwnnel-Blicker/tree/pwnnel-blicker.c

Bla bla demonstration: http://www.youtube.com/watch?v=T6PBfLgEGxM

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: