For mgetty users with non-trusted shell logins
l41484@alfa.ist.utl.pt (l41484@alfa.ist.utl.pt)
Wed, 27 Jan 1999 19:09:49 +0100
On Wed, 27 Jan 1999, Marc SCHAEFER wrote:
> On Wed, 27 Jan 1999 l41484@alfa.ist.utl.pt wrote:
>
> > What are the priveleges for the devices when NO connection is established?
>
> Or, better asked, WHO resets the permissions/owner on those fake
> devices ? :)
I think i've understood where u are trying to get at. (like i previously
said, "i think i've understand,how this is exploited")
What i was trying to understand _now_ is (which had nothing to do with
the vulnerability) : how can users dial out (like gert said). (without
using root suid code off course).
BTW when are u going to release the bomb on bugtraq? I think the
discussion will be quite interesting to watch.
--
Tiago Pascoal (l41484@alfa.ist.utl.pt) FAX : +351-1-7273394
Politicamente incorrecto, e membro (nao muito) proeminente da geracao rasca.