OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-Disclosure] MS Windows Screensaver Privilege Escalation

From: Andrew Farmer (andfarmteknovis.com)
Date: Wed Dec 01 2004 - 16:22:30 CST


On 30 Nov 2004, at 20:50, Andrew Kennedy wrote:
> in fact, under OSX, there is by default no 'root' user -

False. A root user always exists, but generally does not have a
password set.

> it must be specially asked for and created, as part of the 'BSD'
> package.

False. The BSD package just installs command-line tools.

> i won't say apple have gotten things perfect, for example the
> 'Applications'
> folder is writeable by any user

False. Only administrators can write to /Applications.

(The permissions are set to 775; the ownership is set to root:admin.)

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (Darwin)

iD8DBQFBrkQmPa6RRaKl0ScRAsBlAKC1jiIu96fgD/0wxTp3hOnB/VplrwCZAQgp
UQyYJyfCg/ln8BRT9Id3p3M=
=Bq+j
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html