From owner-freebsd-security Thu Jul 12 9: 7:15 2001 Delivered-To: freebsd-security@freebsd.org Received: from dandelion.geeksimplex.org (cc53440-a.catv1.md.home.com [24.18.90.197]) by hub.freebsd.org (Postfix) with ESMTP id 842A737B401 for ; Thu, 12 Jul 2001 09:07:08 -0700 (PDT) (envelope-from icognito@geeksimplex.org) Received: from icognito by dandelion.geeksimplex.org with local (Exim 3.22 #1 (Debian)) id 15Kizb-0000m4-00 for ; Thu, 12 Jul 2001 12:07:07 -0400 Date: Thu, 12 Jul 2001 12:07:06 -0400 From: Gabriel Rocha To: security@FreeBSD.ORG Subject: Re: FreeBSD 4.3 local root Message-ID: <20010712120706.B1020@geeksimplex.org> Mail-Followup-To: security@FreeBSD.ORG Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <075701c10aeb$a7639c40$2001a8c0@clitoris> User-Agent: Mutt/1.3.18i Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org ,----[ On Thu, Jul 12, at 05:59PM, Przemyslaw Frasunek wrote: ]-------------- | riget:venglin:~> ./dupa | vvfreebsd. Written by Georgi Guninski | shall jump to bfbffe72 | child=81380 | Password:done | | # id | uid=0(root) gid=1001(users) groups=1001(users), 99(rexec) `----[ End Quote ]--------------------------- about how long does the exploit run before giving you a root shell? --gabe -- "It's not brave if you're not scared." To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message