Re: Root shell vixie cron exploit

From: Michal Zalewski (lcamtufat_private)
Date: Wed Sep 01 1999 - 12:08:56 PDT

  • Next message: Taneli Huuskonen: "Re: Babcia Padlina Ltd. security advisory: mars_nwe buffer"

    On Wed, 1 Sep 1999, Seva Gluschenko wrote:
    
    > man sendmail:
    > /-C
    > ...skipping...
    > 	-Cfile  Use alternate configuration file.  Sendmail refuses to run
    > 		as root if an alternate configuration file is specified.
    >
    > and it does, for sure %-).
    >
    > Just tested this on different versions of FreeBSD and had no effects
    > except Mail Delivery message:
    >
    > The following address has permanent fatal errors:
    > -C/tmp/vixie-cf gvs
    >
    > So, sendmail _really_ refuses to accept -C key when run as root
    
    Probably you have some problems with understanding written word ;P REFUSES
    TO RUN AS ROOT means: if alternate config file is specified, effective
    root privledges (Setuid) are dropped. But from crond, sendmail is launched
    with uid==euid==0. DOES NOT apply. FreeBSD seems to be patched against
    this attack, that's another issue ;P
    
    _______________________________________________________________________
    Michal Zalewski [lcamtufat_private] [link / marchew] [dione.ids.pl SYSADM]
    [Marchew Industries] ! [http://lcamtuf.na.export.pl] bash$ :(){ :|:&};:
    [voice phone: +48 22 813 25 86] <=-=> [cellular phone: +48 501 4000 69]
    Iterowac jest rzecza ludzka, wykonywac rekursywnie - boska [P. Deutsch]
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:01:23 PDT