Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Why SUID Binary exploit does not yield root shell?

From: Andres Roldan <aroldan(at)fluidsignal.com>
Date: Sun Mar 09 2003 - 12:21:06 EST

Brian Hatch <vuln-dev@ifokr.org> writes:

>> I've managed to find a buffer overflow and exploit it to exeve a /bin/sh

That's true, but in this case he also tried with another buggy suid binary (at least that's what he said) and it _did_ work. If it were a bash protection technique, none of the buggy binaries could have given a root shell.

> Instead of using /bin/sh during your test, try /usr/bin/id just to

That is actually the only way I know to get a root bash prompt with the last bash versions

>
> Compile, install, and call that instead. You should probably just

csh isn't actually an unpleasant shell :)

Do you need help?X

> or any pretty much other shell-like program.

-- 
Andres Roldan 
CSO, Fluidsignal Group S.A.
Received on Mon Mar 10 17:37:43 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:38 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library