BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: 7a69Adv#22 - UNIX unzip keep setuid and setgid files Mar 01 2005 07:44PM
exon (exon home se)
Han Boetes wrote:
> John Simpson wrote:
>
>>this only works if the user un-zipping the file is already root.
>>otherwise it creates an "sh" binary which is setuid to the user
>>who unzipped the file. this kind of "exploit" is only useful if
>>you can somehow trick root into unzipping the file- it c...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus