Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: dinodino
How unsurprising that if you give hackers shell accounts, they can get root!

Gee, what were those AIX and Solaris admins thinking when they gave all us users shell accounts? Come to think of it, they never did get hacked through the shell, so maybe it's a problem unique to OS X.

71 posted on 03/06/2006 9:48:10 PM PST by Senator Bedfellow
[ Post Reply | Private Reply | To 53 | View Replies ]


To: Senator Bedfellow

(1) How do you know they never got hacked?
(2) Were they giving shell access to skilled hackers?
(3) Were they telling the hjackers from 2 it was ok to hack the box?


80 posted on 03/07/2006 6:19:22 AM PST by N3WBI3 (If SCO wants to go fishing they should buy a permit and find a lake like the rest of us..)
[ Post Reply | Private Reply | To 71 | View Replies ]

To: Senator Bedfellow
Gee, what were those AIX and Solaris admins thinking when they gave all us users shell accounts? Come to think of it, they never did get hacked through the shell, so maybe it's a problem unique to OS X.

I'd like to know a lot more about the conditions of the test. If the guy was dumb enough to allow random users shell access, (I'm assuming through SSH, though there is no way to know it - it could have been telnet!),  it would be nice to know if he did anything at all to secure the box. If he was running an http server, did he allow user mods of cgi directories?

Frankly there is is not nearly enough information in the article to tell if this was anywhere close to a valid test.

81 posted on 03/07/2006 6:56:57 AM PST by zeugma (Anybody who says XP is more secure than OS X or Linux has been licking toads.)
[ Post Reply | Private Reply | To 71 | View Replies ]

To: Senator Bedfellow
Gee, what were those AIX and Solaris admins thinking when they gave all us users shell accounts? Come to think of it, they never did get hacked through the shell

Solaris really is immune to privilege elevation exploits. Oops, found one.

And don't forget AIX.

89 posted on 03/07/2006 9:23:20 AM PST by antiRepublicrat
[ Post Reply | Private Reply | To 71 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson