Re: [Full-Disclosure] UNIX Tar Security Advisory from TEAM PWN4GE

2005-02-02 Thread Niek
On 2/2/2005 9:32 PM +0100, Team Pwnge wrote: Connecting to www.(PROTECTEDSITENAME).net[198.81.129.100]:80... connected. nice ip, next advisory please; not. Niek ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-Disclosure] UNIX Tar Security Advisory from TEAM PWN4GE

2005-02-02 Thread Chris Howells
On Wednesday 02 February 2005 22:18, Volker Tanger wrote: So the problem is not TAR, but the cracked wide-open system, that was misconfigured against all defaults and standards. I have a feeling that it was intended as a joke. Unfortunately I tried hard to find it funny. Oh I tried hard. I

Re: [Full-Disclosure] UNIX Tar Security Advisory from TEAM PWN4GE

2005-02-02 Thread Valdis . Kletnieks
On Wed, 02 Feb 2005 23:18:12 +0100, Volker Tanger said: Alternatively the TAR binary might be SUID'ed, which is A Bad Idea(TM), too - which are all SUID'ed programs that can write to arbitrary locations... And in the prehistoric dawn of the computer era, about 15 years ago, IBM made one of