Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Mac OS X Cocktail 3.5.4 admin password disclosure |
|---|---|
| Date: | Fri, 29 Apr 2005 11:48:15 -0700 |
Application: Mac OS X Cocktail Version: 3.5.4 and probably below URL: www.macosxcocktail.com Vulnerability: admin password disclosure ======================================================= Vendor's description: "Cocktail is a general purpose utility for Mac OS X. The application serves up a scrumptious mix of maintenance tools and interface tweaks, all accessible via a comprehensive graphical interface and toolset. It is a smooth and powerful utility that simplifies the use of advanced UNIX functions." The problem: Since Cocktail needs administrative privileges the user is prompted for the admin password upon startup. The actual maintenance is done by command line utilities that are executed in an insecure manner: Cocktail creates a new process and lets /bin/sh pipe the admin password using echo into sudo, which then will execute the utility, like this: sh -c echo 'PASSWORD' | sudo -p "" -S sudo update_prebinding -root / Exploitation: Knowing Cocktail is waiting for some Unix utility to have finished its work, just execute "ps ax" on the terminal and search for the password. The vendor has been contacted; the new version 3.6 for Mac OS X "Tiger" should have been fixed. I haven't tested this version, though. Concerned about your privacy? Follow this link to get secure FREE email: http://www.hushmail.com/?l=2 Free, ultra-private instant messaging with Hush Messenger http://www.hushmail.com/services-messenger?l=434 Promote security and make money with the Hushmail Affiliate Program: http://www.hushmail.com/about-affiliate?l=427
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [bugtraq] Re: Borland Security Contact, Markus Stenzel |
|---|---|
| Next by Date: | Snmppd SNMP proxy daemon format string exploit, cybertronic |
| Previous by Thread: | DEF CON - New CTF Organizers chosen!, The Dark Tangent |
| Next by Thread: | Snmppd SNMP proxy daemon format string exploit, cybertronic |
| Indexes: | [Date] [Thread] [Top] [All Lists] |