The brk() vulnerability
Posted Dec 3, 2003 5:45 UTC (Wed) by
stuart2048 (subscriber, #6241)
Parent article:
The brk() vulnerability
I too would like to offer a big thumbs up on LWN's coverage of this event. Thanks guys!
One thing puzzles me though. How did the attacker gain unpriviledged shell access to the systems in the first place? Apparently this was done via a sniffed password. But how did this password get sniffed? Was it cleartext on the wire? If so, what was it -- telnet, rlogin, X11 keystrokes?
If this was a network sniff, what was the topology? Where did the sniff happen?
--Stuart
(
Log in to post comments)