Re: [Full-disclosure] Symlink attack techniques



Hi,

thanks for all the replies, I really appreciate this.

> Assuming that the find command will report a directory or file that you
> control, you can use the symlink to overwrite a shell script, and then
> place shell commands into your file name:

Ok I should have been more precise in my previous mail. In this scenario I
don't have control over the output generated by the find command. So
basically the cronjob is something like:

15 4  * * 6  root  /usr/bin/find /home/userA -type f -print > /tmp/report.txt

Consequently as userB I have no way of influencing what information is printed
by the find command to /tmp/report.txt but I can surely
control /tmp/report.txt. Any other ideas of how to exploit this to gain root
access?

Thank you very very much.

All the best,
Werner.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: Access 2007 Technical Questions
    ... you may want to bypass the validation rules such as user clicking on the ... on the form, all validation rules on the active control are processed, ... Enter Event doesn't even take place on the command button cause the ... If you used either of these, there would be no reason to check ...
    (microsoft.public.access.formscoding)
  • Re: Word 2007 -- How Alone Am I?
    ... One more question -- when I open the directory in Word (control O), ... QAT are assigned a Key Tip by the position of the command. ... click the Microsoft Office Button and then click New. ... and then click "Add to Quick Access Toolbar". ...
    (microsoft.public.office.misc)
  • Re: Required reading for HP executives
    ... the other 2 will still control ... harware in it to decide which command has majority when it gets multiple ... The mid tier is the "server side" management ... Each MDM ...
    (comp.os.vms)
  • RE: GoToControl or SetFocus problem
    ... the OnClick Event of the button to print the report. ... > When user clicks a command button to preview a report, ... > What I am trying to do, is get the focus back on to the control which is ... > xxx can't move the focus to the control 'StartDate' ...
    (microsoft.public.access.formscoding)
  • Re: Form Date Issue
    ... > I've looked hi & lo for the start date and end date control but can't find ... >> Print a Report? ... Just click the command button on the form to proceed ... Make this query the record source of your report. ...
    (microsoft.public.access.forms)