Bugtraq mailing list archives

Re: Zolaris 2.5 Exploited.


From: leif () netscape com (Leif Hedstrom)
Date: Thu, 25 Jul 1996 19:49:33 -0700


Jungseok Roh writes:
Wow.. I got a chance to use Ultra Sparc who runs Zolaris 2.5 several days ago

neat...

Fwiw, I believe "admintool" in Solaris-2.5 has exactly the same problem.
/tmp/.group.lock for instance is created 666, no security checks...

Just go to the "Groups" menu, and you'll have a nice and clean /.rhosts
file to play with... :(

-- Leif



Current thread: