RE: openbsd 3.4 ps bug

From: Nash Leon (nashleon_at_yahoo.com.br)
Date: 11/21/03

  • Next message: thanos F_at_rm@k1s: "RE: openbsd 3.4 ps bug"
    Date: Fri, 21 Nov 2003 09:17:07 -0300 (ART)
    To: dom@DeVitto.com, vuln-dev@securityfocus.com
    
    

    Hello, Mrs.!

     --- Dom De Vitto <dom@DeVitto.com> escreveu: > I
    personally think it's interesting that ps does not
    > appear to be
    > well formed (as other, setuid/gid) processes could
    > share this issue,
    > however Kurt's point is valid - if there is no
    > elevation of privilege,
    > this is not a 'security bug'.

    If some other program as sudo(suid root) call ps,
    so this can be used for elevation of privilege,
    in this case, this is dangerous.

    Any program that is not suid root, but is called
    for one suid can be used for elevation privilege.

    > Dom

    Sorry my poor english.

    Best Regards,

    Martin Fallon.
    mercenaries's Club
    http://cdm.frontthescene.com.br/

    ______________________________________________________________________

    Yahoo! Mail: 6MB, anti-spam e antivírus gratuito! Crie sua conta agora:
    http://mail.yahoo.com.br


  • Next message: thanos F_at_rm@k1s: "RE: openbsd 3.4 ps bug"

    Relevant Pages

    • The Weakness of Windows Impersonation Model
      ... The Weakness of Windows Impersonation Model ... Network Service account’s context is elevated to LocalSystem. ... unauthorized privilege elevation. ...
      (Bugtraq)
    • Re: The Weakness of Windows Impersonation Model
      ... I believe Longhorn/Vista will address many of issues that currently affect impersonation. ... A context of MS SQL service running as unique user account is ... unauthorized privilege elevation. ...
      (Bugtraq)
    • RE: Elevate permission of code
      ... As for the privilege elevation, I'm afraid you're limited to the Vista ... Microsoft MSDN Online Support Lead ... where an initial response from the community or a Microsoft Support ...
      (microsoft.public.platformsdk.security)
    • RE: Elevate permission of code
      ... As for the privilege elevation, I'm afraid you're limited to the Vista ... Microsoft MSDN Online Support Lead ... where an initial response from the community or a Microsoft Support ...
      (microsoft.public.platformsdk.security)
    • RE: Elevate permission of code
      ... As for the privilege elevation, I'm afraid you're limited to the Vista ... Just let the UAC detect it and request the user to do the elevation ... Microsoft MSDN Online Support Lead ...
      (microsoft.public.platformsdk.security)