As pointed out in
http://www.osreviews.net/reviews/admin/usermin it is
possible to disable the login shell of the root account
by calling save.cgi with an empty value for the shell.
The problem is that the command is expanded to `chsh -s
foo`, which changes the shell of the root account to
foo instead of changing foo's shell.
When combined with some well-known social engineering
tactics (cf. "Stealing Superuser" in Practical UNIX &
Internet Security) it might even be possible to obtain
root access to the system.
Nobody/Anonymous ( nobody ) - 2006-06-20 08:38
5
Closed
None
Jamie Cameron
Change User Details
None
Public
|
Date: 2006-09-14 16:27 Logged In: YES |
|
Date: 2006-09-14 10:19 Logged In: NO |
|
Date: 2006-06-20 16:47 Logged In: YES |
Copyright © 2010 Geeknet, Inc. All rights reserved. Terms of Use