Finding setuid programs

Ron Natalie ron at BRL-TGR
Wed Feb 6 10:34:47 AEST 1985


I assumme the unkillable program mearly had a copy of itself open that
it could keep writing itself out.  The reason you have to go back to
the distribution tapes is evidenced by something that happened to us
once.  One of our nefarious users modified /lib/crt0 to exec a file
called ^V in the current directory.  I was only a few extra bytes and
all he had to do was wait for it to show up in setuid programs again.

-Ron



More information about the Comp.unix.wizards mailing list