邪恶八进制信息安全团队技术讨论组's Archiver

EvilOctal 2005-1-24 23:27

[转载]fkey Symblink Vulnerability

信息来源:[url]www.securiteam.com[/url]

Summary
fkey is "a scalable finger daemon type server for public display of user-specified files, e.g. PGP keys, contact information, etc. Users edit their data file (supplied as an ASCII text file), and the finger daemon displays it on public request. It may be used as a banner server".

Due to improper usage of local files by fkey, its possible for a local attacker to use the program to gain elevated privileges.

Credit:
The information has been provided by Vade 79.
The original article can be found at: [url]http://fakehalo.us/xfkey.c[/url]

Details
Exploit:
[url]http://www.eviloctal.com/forum/read.php?tid=7032&toread=1&fpage=1[/url]

页: [1]
© 1999-2008 EvilOctal Security Team