OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: How to login to a machine with invalid shell in /etc/passwd?
From: josh (dorqusbsdfreek.com)
Date: Wed Jan 03 2001 - 01:48:05 CST


Raymond Causton wrote...
> The Solaris 7 (v.11/99) install in the bare-bones install with only telnet
> and ftp-services on, no sshd, lpd or httpd (which would have been
> exploitable) and it doesn't seem very vulnerable to any root exploit I could
> find at packetstorm or root shell.

ftp up (as root) a new /etc/default/login file that has the
CONSOLE=/dev/console line commented out. EIther that or
FTP up a new /etc/passwd and /etc/shadow file where root has
the correct path.
If you're using stock Solaris ftpd, it should let you in as root.
(it does in 2.6 anyway)

--
josh