0x90.org

[XSO] Archives? Re : ARDAgent scripting escalation flaw

Andre Ludwig andre.ludwig at gmail.com
Sat Jun 21 14:39:37 EDT 2008

http://www.macshadows.com/forums/index.php?showtopic=8640&st=530

Some interesting stuff there.

Dre

On Sat, Jun 21, 2008 at 2:55 AM, Dalton Cummings <m4cpunk at gmail.com> wrote:

> Seems plenty on topic to me.
>
> While scripting this bug to test other apps on the system, I was able to
> get SecurityAgent.app to execute commands as securityagent. I failed to
> reproduce the issue outside of the Python interactive prompt. Maybe
> someone else could have some fun. Tested on a PowerPC iMac G4 running
> Mac OS X v10.4.11.
>
> osascript -e 'tell app "SecurityAgent" to do shell script "whoami"'
>
> --Dalton
>
> Poindexter Frink wrote:
> > A brief apology if this is not considered on-topic for this list.
> > _______________________________________________
> > XSO mailing list
> > XSO at 0x90.org
> > http://0x90.org/mailman/listinfo/xso
> >
> >
>
> _______________________________________________
> XSO mailing list
> XSO at 0x90.org
> http://0x90.org/mailman/listinfo/xso
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://0x90.org/pipermail/xso/attachments/20080621/e7434706/attachment.htm 

More information about the XSO mailing list