Re: LOGWATCH EXPLOIT ROOT COMPROMISE

2002-04-01 Thread Muhammad Faisal Rauf Danka
you told us about the workaround, but I couldnt find any such security advisory or problem on logwatch's website or other security websites. Could you please wrap it up in some form of an advisory with technical details and let the world know. =) Thank You - Muhammad Faisal Rauf Danka

Re: LOGWATCH EXPLOIT ROOT COMPROMISE

2002-04-01 Thread bailey
Here's the link my good man http://www.securiteam.com/exploits/5OP0S2A6KI.html Can we have some linkage? I didn't find any information about it on logwatch.org or linuxsecurity.com. Cheers, Ash Bailey Kong wrote: if you haven't heard yet, root account can be compromised by a local

LOGWATCH EXPLOIT ROOT COMPROMISE

2002-03-29 Thread Bailey Kong
if you haven't heard yet, root account can be compromised by a local account using logwatch. the current work around i got was to chattr +i /etc/passwd that makes it so /etc/passwd can't be modified, if and when you need to add a user you can simply do chattr -i /etc/passwd i hope no one has

Re: LOGWATCH EXPLOIT ROOT COMPROMISE

2002-03-29 Thread Ash
Can we have some linkage? I didn't find any information about it on logwatch.org or linuxsecurity.com. Cheers, Ash Bailey Kong wrote: if you haven't heard yet, root account can be compromised by a local account using logwatch. the current work around i got was to chattr +i /etc/passwd that

Re: LOGWATCH EXPLOIT ROOT COMPROMISE

2002-03-29 Thread jon schatz
On Thu, 2002-03-28 at 22:14, Bailey Kong wrote: the current work around i got was to chattr +i /etc/passwd that makes it so /etc/passwd can't be modified, if and when you need to add a user you can simply do chattr -i /etc/passwd that's absolutely pointless under linux. the exploit allows