[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4D359394.90102@gmail.com>
Date: Tue, 18 Jan 2011 09:20:20 -0400
From: Emanuel dos Reis Rodrigues <emanueldosreis@...il.com>
To: 我是王子 <tradeprince@...com>
Cc: full-disclosure <full-disclosure@...ts.grok.org.uk>,
bugtraq <bugtraq@...urityfocus.com>, sbeattie <sbeattie@...ntu.com>
Subject: Re: I find a bug
How ?
There is not a bug, it is only work if your sudo configuration is
without password to ALL or the strace command. some distributions have
this configuration to default user.
You can test or give us more details ?
Emanuel dos Reis Rodrigues
Senior Level Linux Professional (LPIC-3)
LPI 302 (Mixed Environment) Specialty
LPI 304 (Virtualization and High Availability) Specialty
C|EH Certified Ethical Hacker
CompTIA Security+ Certified
http://br.linkedin.com/in/emanuelreis
t:@emanueldosreis
emanueldosreis(No*SpAm)gmail.com
Mobile: +55 95 8112-9628
我是王子 wrote:
> hello,
> I found a bug,
> run [sudo strace su] command can get root privileges without any password.
> bill
> ------------------ Original ------------------
> *From: * "Steve Beattie"<sbeattie@...ntu.com>;
> *Date: * Thu, Jan 13, 2011 08:01 PM
> *To: *
> "ubuntu-security-announce"<ubuntu-security-announce@...ts.ubuntu.com>;
> *Cc: * "full-disclosure"<full-disclosure@...ts.grok.org.uk>;
> "bugtraq"<bugtraq@...urityfocus.com>;
> *Subject: * [USN-1042-2] PHP5 regression
> --
> ubuntu-security-announce mailing list
> ubuntu-security-announce@...ts.ubuntu.com
> Modify settings or unsubscribe at:
> https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists