Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 15 Oct 1996 09:38:44 -0700
From:      David Greenman <dg@root.com>
To:        Nathan Lawson <nlawson@kdat.csc.calpoly.edu>
Cc:        marcs@znep.com (Marc Slemko), freebsd-security@freebsd.org
Subject:   Re: bin/1805: Bug in ftpd 
Message-ID:  <199610151638.JAA02562@root.com>
In-Reply-To: Your message of "Tue, 15 Oct 1996 08:53:38 PDT." <199610151553.IAA28499@kdat.calpoly.edu> 

next in thread | previous in thread | raw e-mail | index | archive | help
>one instance of this attack, preventing core dumps.  It is trivial to get 
>around it by using ptrace to attach to the process and read the memory
>containing the encrypted passwords.

   At least in FreeBSD, you can't use ptrace-attach on a process that has
changed its uid.

-DG

David Greenman
Core-team/Principal Architect, The FreeBSD Project



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199610151638.JAA02562>