Re: Sudo: local root compromise with krb5 enabled

2007-06-14 Thread Kyle Wheeler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Monday, June 11 at 06:52 PM, quoth Ken Raeburn: >> But sudo has a curious bug: it *tries* to do the second step, but >> if that step fails because no local service keys are known, it lets >> the user become root anyway, because the (potentially fa

Re: Sudo tricks

2006-03-27 Thread Kyle Wheeler
On Friday, March 24 at 07:05 PM, quoth Dave Korn: Here is a simple hack to break sudo and su to get free root. Add this to ~/.bashrc and fill in the following blanks: * ~/.root_kit/rk_su Your hacked su to give root on su --now-dammit * ~/.root_kit/silent_install_root_kit Your script to silent

Re: IE BUG, Mozilla DOS?

2005-11-23 Thread Kyle Wheeler
On Monday, November 21 at 08:20 PM, quoth [EMAIL PROTECTED]: The IE bug shown in the advisory here http://www.computerterrorism.com/research/ie/ct21-11-2005 seems to have a DDOS like effect on mozilla sending pc usage to 99 % until mozilla either crashes or gives way. This bug seems to make