Hi, On 25 Apr 2002, Alexandru Balan wrote:
> ba.. deci don't shoot da' keygen nu e apropos de ssh ? I'm not shootin', just hunting (see signature)... > si sshd-u meu e configurat sa nu permita root login Nu are a face, si e vorba de keyinit, de fapt. Din "FreeBSD-SA-02:23.stdio": - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - II. Problem Description Some programs are set-user-id or set-group-id, and therefore run with increased privileges. If such a program is started with some of the stdio file descriptors closed, the program may open a file and inadvertently associate it with standard input, standard output, or standard error. The program may then read data from or write data to the file inappropriately. If the file is one that the user would normally not have privileges to open, this may result in an opportunity for privilege escalation. III. Impact Local users may gain superuser privileges. It is known that the `keyinit' set-user-id program is exploitable using this method. There may be other programs that are exploitable. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Standard disclaimer: eu n-am incercat, YMMV. Ady (@rofug.ro) _____________________________________________________________________ | "Be vewy vewy quiet, I'm hunting wuntime ewwors!..." (Elmer Fudd) | __________________________________________________________ Send 'unsubscribe rofug' to [EMAIL PROTECTED] to unsubscribe

