[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] I find a bug



How ?

There is not a bug, it is only work if your sudo configuration is without password to ALL or the strace command. some distributions have this configuration to default user.

You can test or give us more details ?


Emanuel dos Reis Rodrigues
Senior Level Linux Professional (LPIC-3) LPI 302 (Mixed Environment) Specialty
LPI 304 (Virtualization and High Availability) Specialty
C|EH Certified Ethical Hacker
CompTIA Security+ Certified
http://br.linkedin.com/in/emanuelreis
t:@emanueldosreis
emanueldosreis(No*SpAm)gmail.com
Mobile: +55 95 8112-9628








ÎÒÊÇÍõ×Ó wrote:
hello,
I found a bug,
run [sudo strace su] command can get root privileges without any password.
bill
------------------ Original ------------------
*From: * "Steve Beattie"<sbeattie@xxxxxxxxxx>;
*Date: * Thu, Jan 13, 2011 08:01 PM
*To: * "ubuntu-security-announce"<ubuntu-security-announce@xxxxxxxxxxxxxxxx>; *Cc: * "full-disclosure"<full-disclosure@xxxxxxxxxxxxxxxxx>; "bugtraq"<bugtraq@xxxxxxxxxxxxxxxxx>;
*Subject: * [USN-1042-2] PHP5 regression
--
ubuntu-security-announce mailing list
ubuntu-security-announce@xxxxxxxxxxxxxxxx
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

------------------------------------------------------------------------

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/