Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
DEAL: For $25 - Add A Second Phone Number To Your Smartphone for life! Use promo code SLASHDOT25. Also, Slashdot's Facebook page has a chat bot now. Message it for stories and more. Check out the new SourceForge HTML5 internet speed test! ×
Sun Microsystems

Submission + - Trivial Remote Exploit on Sun Solaris 10

Jeremy Kister writes: "Errata Security reports about a bug found in the telnet daemon of Solaris 10. From the article:

Basically if you pass a "-fusername" as an argument to the -l option you get full access to the OS as the user specified. In my example I do it as bin but it worked for regular users, just not for root. This combined with a reliable local privilege escalation exploit would be devastating. Expect mass scanning and possibly the widespread exploitation of this vulnerability.
"

Slashdot Top Deals

The only perfect science is hind-sight.

Working...