On Tue, 29 Jan 2008 07:57:39 +0800, Eduardo Tongson said:
> kernel used is fully updated and root SSH login dismissed do you know
> a way of getting root without an unknown kernel bug?
The *vast* majority of "get r00t kwik" exploits do *not* involve exploiting
kernel bugs, but involve exploiting daemon processes running as root or
set-UID programs. So if you have CUPS running, they don't need a kernel
exploit, they just need a CUPS exploit (and CUPS *has* had a few issues).
Same for Sendmail, NTP, the X server, or any of the other things found on
the average Unix/Linux install....
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001
> kernel used is fully updated and root SSH login dismissed do you know
> a way of getting root without an unknown kernel bug?
The *vast* majority of "get r00t kwik" exploits do *not* involve exploiting
kernel bugs, but involve exploiting daemon processes running as root or
set-UID programs. So if you have CUPS running, they don't need a kernel
exploit, they just need a CUPS exploit (and CUPS *has* had a few issues).
Same for Sendmail, NTP, the X server, or any of the other things found on
the average Unix/Linux install....
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001
iD8DBQFHn3eJcC3lWbTT17ARApo8AJ4qPOb8GmQIG/ubAoq2KCjYlN+xnwCgyt4k
dW3o7Tn80584t2Kc+D4V0t0=
=bCMx
-----END PGP SIGNATURE-----
[ reply ]