Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 10 Aug 1997 10:22:53 +0000 (GMT)
From:      "Jonathan A. Zdziarski" <jonz@netrail.net>
To:        Brian Mitchell <brian@firehouse.net>
Cc:        bugtraq@netspace.org, freebsd-security@FreeBSD.ORG
Subject:   Re: procfs hole
Message-ID:  <Pine.BSF.3.95q.970810102208.13506A-100000@netrail.net>
In-Reply-To: <Pine.NEB.3.96.970810052824.3287A-100000@apocalypse.saturn.net>

next in thread | previous in thread | raw e-mail | index | archive | help
I attempted to run it and got the following trying to run it with 'root'
as the user (even providing the correct password):

Demonstration of 4.4BSD procfs hole
Brian Mitchell <brian@firehouse.net>

after you see "setuid changed", enter the pw for the user
Be warned, searching for the setuid() function takes a long time!
Password:searching - please be patient...
setuid changed (0x8046f64)

_su: Permission denied.

I'm running freebsd 2.2.2

-------------------------------------------------------------------------
Jonathan A. Zdziarski                                NetRail Incorporated
Server Engineering Manager                    230 Peachtree St. Suite 500
jonz@netrail.net                                        Atlanta, GA 30303
http://www.netrail.net                                    (888) - NETRAIL
------------------------------------------------------------------------- 




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.95q.970810102208.13506A-100000>