Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Mac symlink attack techniques? |
|---|---|
| Date: | Fri, 11 Apr 2008 12:23:00 -0600 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 If this is a server, just create root's .ssh/authorized_keys file. If it ends up world rw just remember that you have to change modes so it is not world rw for sshd to use it. If this is a desktop-only app, do the same to a user's account that has information you want. You don't need root on MacOSX to compromise it unless it's a server. Another fun technique is to create a user's .bash_profile or .bashrc if it isn't already created. I can't remember if MacOSX gives you a bash shell by default, but every shell has a similar file. If MacOSX creates these files for its users, there are still other tricks. If they don't have a .bash_history file, for example, you can create one with fake commands. So when they execute history it'll install a trojan or some such other thing. There are 1,000+1 more techniques here, these are just lame examples. Just get creative :-) D -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) iD8DBQFH/6x+yWX0NBMJYAcRAnFMAJ0RasxlGonM53hd6gsUe4HencDIyQCfWDzx q55hwtLHLUoOS5jzExTAWn4= =4dvF -----END PGP SIGNATURE----- ------------------------------------------------------------------------ This list is sponsored by: Cenzic Need to secure your web apps NOW? Cenzic finds more, "real" vulnerabilities fast. Click to try it, buy it or download a solution FREE today! http://www.cenzic.com/downloads ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: get MD5-Hash from /etc/shadow file, Razi Shaban |
|---|---|
| Next by Date: | Re: get MD5-Hash from /etc/shadow file, Larry Offley |
| Previous by Thread: | Mac symlink attack techniques?, Jon Hart |
| Next by Thread: | Re: Mac symlink attack techniques?, Paul Melson |
| Indexes: | [Date] [Thread] [Top] [All Lists] |