OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 3rd quarter (Jul-Sep) 1994: setuid root programs and core dumps

setuid root programs and core dumps

Rob Quinn (rjqphys.ksu.edu)
Thu, 21 Jul 1994 21:28:52 -0500 (CDT)

>If you setuid to root and run it as someone other than root, it just
>does a bus error and doesn't core dump!

 Wasn't LD_LIBRARY_PATH also ignored by setuid programs? But people were still
able to use it to break into root programs. Maybe something similar can be
done here?

-- 
|                                                                          |
|                                                                Rob Quinn |
|                                                         rjqphys.ksu.edu |
|                                                    QuinnBobKSUVM.BITNET |