Re: /lib/ld-2.2.4.so

From: Eric Rostetter (eric.rostetterat_private)
Date: Tue Apr 23 2002 - 07:12:43 PDT

  • Next message: FozZy: "Re: Cross site scripting in almost every mayor website"

    Quoting Sabau Daniel <dravenat_private>:
    
    > 	This file gives users the ability of running binaries on witch the 
    > user doesn't have the permission to execute, it is enough to have read 
    > ability on the file in order to execute it:
    > 
    > -rwxr-xr--    1 root     root        45948 Aug  9  2001 /bin/ls
    > 
    > but using the /lib/ld-2.2.4.so file i can execute the ls command:
    > 
    > [08:51:36][draven@Zero:~]:$/lib/ld-2.2.4.so /bin/ls /
    > bin   bzImage   bzImage3  bzImage5  dev  home    lib   mnt  proc  sbin  
    > usr
    > boot  bzImage2  bzImage4  bzImage6  etc  initrd  misc  opt  root  tmp   
    > var
    
    This is a old, known issue.  I've known about it for about 2 years, and
    I'm sure others have known about it longer.  It makes an appearance on
    a mailing list about once a year.
    
    I know of no solution though to all the problems this brings up.
    
    -- 
    Eric Rostetter
    eric.rostetterat_private
    
    Hey Rocky!  Watch me pull a rabbit from my hat!
    



    This archive was generated by hypermail 2b30 : Wed Apr 24 2002 - 13:37:53 PDT