[ advisories | exploits | discussions | news | conventions | security tools | texts & papers ]
 main menu
- feedback
- advertising
- privacy
- FightAIDS
- newsletter
- news
 
 discussions
- read forum
- new topic
- search
 

 meetings
- meetings list
- recent additions
- add your info
 
 top 100 sites
- visit top sites
- sign up now
- members
 
 webmasters

- add your url
- add domain
- search box
- link to us

 
 projects
- our projects
- free email
 
 m4d network
- security software
- secureroot
- m4d.com
Home : Advisories : RH 6.1/6.2 minicom vulnerability

Title: RH 6.1/6.2 minicom vulnerability
Released by: Michal Zalewski
Date: 21st August 2000
Printable version: Click here
On RedHat 6.1 and RedHat 6.2 boxes (I haven't found other distributions

vulnerable):



@(#)Minicom V1.83.0 (compiled Mar  7 2000)(c) Miquel van Smoorenburg



[lcamtuf@nimue lcamtuf]$ minicom -C foo

minicom: there is no global configuration file /etc/minirc.dfl

Ask your sysadm to create one (with minicom -s).



[lcamtuf@nimue lcamtuf]$ ls -l foo

-rw-rw-r--   1 lcamtuf  uucp            0 Aug 18 12:21 foo

    ^^                  ^^^^



Any file can be created anywhere with uucp privledges - it will follow

symlinks. Not nice on systems running uucp services.



_______________________________________________________

Michal Zalewski [lcamtuf@tpi.pl] [tp.internet/security]

[http://lcamtuf.na.export.pl] <=--=> bash$ :(){ :|:&};:

=-----=> God is real, unless declared integer. <=-----=



-- Support your government, give Echelon / Carnivore something to parse --

classfield  top-secret government  restricted data information project CIA

KGB GRU DISA  DoD  defense  systems  military  systems spy steal terrorist

Allah Natasha  Gregori destroy destruct attack  democracy will send Russia

bank system compromise international  own  rule the world ATSC RTEM warmod

ATMD force power enforce  sensitive  directorate  TSP NSTD ORD DD2-N AMTAS

STRAP warrior-T presidental  elections  policital foreign embassy takeover

--------------------------------------------------------------------------








(C) 1999-2000 All rights reserved.