[Full-disclosure] I find a bug

Emanuel dos Reis Rodrigues emanueldosreis at gmail.com
Tue Jan 18 13:20:20 GMT 2011


How ?

There is not a bug, it is only work if your sudo configuration is 
without password to ALL or the strace command. some distributions have 
this configuration to default user.

You can test or give us more details ?


Emanuel dos Reis Rodrigues
Senior Level Linux Professional (LPIC-3) 
LPI 302 (Mixed Environment) Specialty
LPI 304 (Virtualization and High Availability) Specialty
C|EH Certified Ethical Hacker
CompTIA Security+ Certified
http://br.linkedin.com/in/emanuelreis
t:@emanueldosreis
emanueldosreis(No*SpAm)gmail.com
Mobile: +55 95 8112-9628








ÎÒÊÇÍõ×Ó wrote:
> hello,
> I found a bug,
> run [sudo strace su] command can get root privileges without any password.
> bill
> ------------------ Original ------------------
> *From: * "Steve Beattie"<sbeattie at ubuntu.com>;
> *Date: * Thu, Jan 13, 2011 08:01 PM
> *To: * 
> "ubuntu-security-announce"<ubuntu-security-announce at lists.ubuntu.com>;
> *Cc: * "full-disclosure"<full-disclosure at lists.grok.org.uk>; 
> "bugtraq"<bugtraq at securityfocus.com>;
> *Subject: * [USN-1042-2] PHP5 regression
> -- 
> ubuntu-security-announce mailing list
> ubuntu-security-announce at lists.ubuntu.com
> Modify settings or unsubscribe at: 
> https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/



Full-Disclosure is hosted and sponsored by Secunia.