OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 3rd quarter (Jul-Aug) 1995: Re: Exploit for Linux wu.ftpd hole

Re: Exploit for Linux wu.ftpd hole

bt (btcyberflunk.com)
Wed, 5 Jul 1995 18:46:58 -0700

You have to run as root to setuid to the user, to open the log files,
and to chroot (for anon) to the ftp dir.. of course after login, root
privs are not really needed.

On Wed, 5 Jul 1995, John Adams wrote:

> Ahh, but isn't wu-ftp supposed to be running as uid ftp?
>
> where does the turnabout come in where ftpd runs as ROOT?
>
> (I haven't been at the source yet, so I'm just throwing these
>  questions out for discussion..)
>
> -john
>