Possible exploit in 5.4-STABLE

[ Available lists | Index of freebsd-stable | Month of Jul 2005 | Week of 1 Jul 2005 | Raw email | View thread | Wrap long lines | Reply | Tag ]
From
Argelo, Jorn <jorn_argelo@epson-europe.com>
Date
1 Jul 2005 13:50:25
Subject
Possible exploit in 5.4-STABLE
Message-ID
42C54F34.3070003@epson-europe.com

Referenced by

[ Hide this part ]
Hi all,

My site has been cracked yesterday (don't worry it's not about that) and
the cracker uploaded a script to delete stuff. Anyway, not important.
The script contained a link to a russian site.

This site, of course (almost) completely in Russian, had a file to gain
root access with a modified su utility. It's maybe not so useful for me
to attach the binary, but I'll do it anyway because I don't have
anything else but that and a readme file. It didn't seem to work (out of
the box) with 5.4-RELEASE though.

This is a translation from babelfish:

Plain replacement of "standard" su for FreeBSD. It makes it possible to
become any user (inc. root) with the introduction of any password. For
this necessary to neglect su with the option "-!". with the use of this
option does not conduct ravine- files. Was tested on FreeBSD 5.4-STABLE.

My apologies if I am sending in something completely useless and not
important, but I figured it wouldn't hurt just to make sure.

Cheers,

Jorn.




[ Show this part (application/octet-stream) ]

Elapsed time: 0.113 seconds