0x90.org

[XSO] Archives? Re : ARDAgent scripting escalation flaw

Dalton Cummings m4cpunk at gmail.com
Sat Jun 21 02:55:09 EDT 2008

Seems plenty on topic to me.

While scripting this bug to test other apps on the system, I was able to 
get SecurityAgent.app to execute commands as securityagent. I failed to 
reproduce the issue outside of the Python interactive prompt. Maybe 
someone else could have some fun. Tested on a PowerPC iMac G4 running 
Mac OS X v10.4.11.

osascript -e 'tell app "SecurityAgent" to do shell script "whoami"'

--Dalton

Poindexter Frink wrote:
> A brief apology if this is not considered on-topic for this list.
> _______________________________________________
> XSO mailing list
> XSO at 0x90.org
> http://0x90.org/mailman/listinfo/xso
>
>   

More information about the XSO mailing list