Re: Mac OS X setuid root security hole

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wednesday, October 17, 2001, at 09:53 , rotaiv wrote:
> I can't recall if I have seen this on BugTraq so forgive me if this is 
> an old issue.
>
> Try these steps on an OS X machine (not logged in as root)
>
>  - Open up the terminal application
>  - Quit the terminal application
>  - Open up NetInfo Manager (leave it in the foreground)
>  - Open up the Terminal application form the "Recent Items" list in the 
> Apple Menu.
>
> You should now be logged in as root!

This also affects items in the Services menu (want a root text editor?), 
which suggests
the entire menu handler runs as the effective userid.

Chris


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux