Re: RedHat 6.1 /and others/ PAM

From: Simple Nomad (thegnomeat_private)
Date: Tue Feb 01 2000 - 15:01:33 PST

  • Next message: Miles Sabin: "Re: "Strip Script Tags" in FW-1 can be circumvented"

    Maybe I should restate. The sploit as it stands didn't work, and even
    using expect, pty, etc didn't work. Still showing up in syslog on RH 6.1,
    can someone else confirm/deny?
    
    -         Simple Nomad          -  No rest for the Wicca'd  -
    -      thegnomeat_private        -        www.nmrc.org       -
    -  thegnomeat_private  -      www.bindview.com     -
    
    On Tue, 1 Feb 2000, Pavel Kankovsky wrote:
    
    > On Mon, 31 Jan 2000, Simple Nomad wrote:
    >
    > > Trying to "echo PASSWORD | su ACCOUNT" will elicit a response of
    > > "standard in must be a tty..." therefore the sploit would stop on the
    > > first word in the list as if it was the correct password. Therefore I fail
    > > to see the exact sploit here. I tried this on a stock RH 6.1 machine.
    >
    > Use a pseudoterminal. Expect is your friend.
    >
    > --Pavel Kankovsky aka Peak  [ Boycott Microsoft--http://www.vcnet.com/bms ]
    > "Resistance is futile. Open your source code and prepare for assimilation."
    >
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:32:56 PDT