[iwar] [fc:Mac.OS.X.setuid.root.security.hole]

From: Fred Cohen (fc@all.net)
Date: 2001-10-17 18:32:53


Return-Path: <sentto-279987-3068-1003368778-fc=all.net@returns.onelist.com>
Delivered-To: fc@all.net
Received: from 204.181.12.215 by localhost with POP3 (fetchmail-5.1.0) for fc@localhost (single-drop); Wed, 17 Oct 2001 18:34:08 -0700 (PDT)
Received: (qmail 20915 invoked by uid 510); 18 Oct 2001 01:32:36 -0000
Received: from n33.groups.yahoo.com (216.115.96.83) by 204.181.12.215 with SMTP; 18 Oct 2001 01:32:36 -0000
X-eGroups-Return: sentto-279987-3068-1003368778-fc=all.net@returns.onelist.com
Received: from [10.1.4.52] by n33.groups.yahoo.com with NNFMP; 18 Oct 2001 01:32:58 -0000
X-Sender: fc@big.all.net
X-Apparently-To: iwar@onelist.com
Received: (EGP: mail-8_0_0_1); 18 Oct 2001 01:32:57 -0000
Received: (qmail 68406 invoked from network); 18 Oct 2001 01:32:57 -0000
Received: from unknown (10.1.10.27) by m8.onelist.org with QMQP; 18 Oct 2001 01:32:57 -0000
Received: from unknown (HELO big.all.net) (65.0.156.78) by mta2 with SMTP; 18 Oct 2001 01:32:57 -0000
Received: (from fc@localhost) by big.all.net (8.9.3/8.7.3) id SAA05396 for iwar@onelist.com; Wed, 17 Oct 2001 18:32:53 -0700
Message-Id: <200110180132.SAA05396@big.all.net>
To: iwar@onelist.com (Information Warfare Mailing List)
Organization: I'm not allowed to say
X-Mailer: don't even ask
X-Mailer: ELM [version 2.5 PL1]
From: Fred Cohen <fc@all.net>
X-Yahoo-Profile: fcallnet
Mailing-List: list iwar@yahoogroups.com; contact iwar-owner@yahoogroups.com
Delivered-To: mailing list iwar@yahoogroups.com
Precedence: bulk
List-Unsubscribe: <mailto:iwar-unsubscribe@yahoogroups.com>
Date: Wed, 17 Oct 2001 18:32:53 -0700 (PDT)
Reply-To: iwar@yahoogroups.com
Subject: [iwar] [fc:Mac.OS.X.setuid.root.security.hole]
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

  - Open up the terminal application
  - Quit the terminal application
  - Open up NetInfo Manager (leave it in the foreground)
  - Open up the Terminal application form the "Recent Items" list in 
the Apple Menu.

You should now be logged in as root!

confirmed on osx 10.1 with all available updates (none)

[malaria:~] floh% uname -a
Darwin malaria 1.4 Darwin Kernel Version 1.4: Sun Sep  9 15:39:59 PDT 
2001; root:xnu/xnu-201.obj~1/RELEASE_PPC  Power Macintosh powerpc


cheers floh

------------------------ Yahoo! Groups Sponsor ---------------------~-->
Pinpoint the right security solution for your company- Learn how to add 128- bit encryption and to authenticate your web site with VeriSign's FREE guide!
http://us.click.yahoo.com/yQix2C/33_CAA/yigFAA/kgFolB/TM
---------------------------------------------------------------------~->

------------------
http://all.net/ 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/ 



This archive was generated by hypermail 2.1.2 : 2001-12-31 20:59:55 PST