FC6 and cdburning

Leszek Matok Lam at Lam.pl
Sat Jul 29 17:41:56 UTC 2006


Dnia 29-07-2006, sob o godzinie 19:26 +0200, dragoran napisał(a):
> > If you can issue such commands to the drive, you can easily:
> > - become root
> how could this lets a user become root?
Maybe he was thinking about sending commands to any drive? Speaking to
hard disk drive one can edit /etc/passwd and so on. But we're talking
about CD drives, how can a CD drive make me root? People have suid
cdrecords on machines with shell accounts and to this point there was no
exploit using SCSI commands to gain privileges (the only one I know of
was using user-provided $RSH as root).

Lam
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: To jest cz??? listu	podpisana cyfrowo
URL: <http://listman.redhat.com/archives/fedora-devel-list/attachments/20060729/c19ca8f9/attachment.sig>


More information about the fedora-devel-list mailing list