BugTraq
crontab from vixie-cron allows read other users crontabs Apr 06 2005 10:00AM
Karol Wiêsek (appelast drumnbass art pl) (3 replies)
Re: crontab from vixie-cron allows read other users crontabs Apr 06 2005 09:31PM
David Malone (dwmalone maths tcd ie)
Re: crontab from vixie-cron allows read other users crontabs Apr 06 2005 08:24PM
Gadi Evron (ge linuxbox org)
Re: crontab from vixie-cron allows read other users crontabs Apr 06 2005 04:51PM
Richard Moore (rich westpoint ltd uk)


Karol Wiêsek wrote:
> but also checks entrys, so attacker is only able to read properly
> formated crontab files (another users crontabs).

It should be noted that files other than crontabs are valid
files as far as cron is concerned. This is because crontabs
may contain variable assignments and comments. This means
that it may be possible to read other configuration files
or scripts that confirm to the syntax used by cron.

Cheers

Rich.
--
Richard Moore, Principle Software Engineer,
Westpoint Ltd,
Albion Wharf, 19 Albion Street, Manchester, M1 5LN, England
Tel: +44 161 237 1028
Fax: +44 161 237 1031

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus