exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Linbert.txt

Linbert.txt
Posted Feb 16, 2000
Authored by Grampa Elite

Linberto v1.0.2 (Q-Bert linux clone) can overwrite any file on the system, via insecure use of /tmp.

tags | exploit
systems | linux
SHA-256 | 6c7927b9fd086ea0c82ab43be5519e598d06858818773d8713d6cdf708f9508a

Linbert.txt

Change Mirror Download

Vulnerability: Any user can overwrite any file in the system.
title=Linberto v1.0.2 (Q-Bert clone)
author=diego@grigna.com (Diego Javier Grigna)
system=Linux, svgalib
foundby=grampae@netwurx.net (Grampa Elite)

Overview: Linberto under default installation creates screenshots under
the /tmp directory when the user presses F1. Take a look at this snippet from
the installation docs.
-------------------------------begin-screenshot.txt----------------------------
When you press F1 anywhere when running the game, a screen shot
of the current screen will be saved to the directory LINBERTO_SCREENSDIR
which is (by default in the Makefile) /tmp/.

The program makes two files:

LINBERTO_SCREENSDIR/linbertossXXXX.raw ---> Which contains the image data
(the byte of each pixel).

and

LINBERTO_SCREENSDIR/linbertossXXXX.pal ---> Which contains the palette in
the format:
"Color index, Red, Green, Blue\n"


The "XXXX" in the filename is a number from 0000 to 9999. Each time a
screen shot is made, the program will try to use the lowest possible
number (0000 by default) if that file exists that number will be incre-
mented by one, until a non existing filename is found.
-------------------------------end-screenshot.txt------------------------------

The problem is that it does not check to see if the file linbertossXXXX.pal
is currently there as Diego says it does, and follows symlinks. Linberto is not
root suid which actually does not matter, since this is a console game for X
that installs executable only by root.
So as an example we would do a "ln -s /etc/passwd /tmp/linbertoss0000.pal"
or any other file you would like to overwrite, and wait for root to play
linberto and take a screen capture. If the linbertossXXXX.pal and .raw
files are already in /tmp, just use the next number.
Login or Register to add favorites

File Archive:

March 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    13 Files
  • 3
    Mar 3rd
    15 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    16 Files
  • 7
    Mar 7th
    31 Files
  • 8
    Mar 8th
    16 Files
  • 9
    Mar 9th
    13 Files
  • 10
    Mar 10th
    9 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    10 Files
  • 14
    Mar 14th
    6 Files
  • 15
    Mar 15th
    17 Files
  • 16
    Mar 16th
    22 Files
  • 17
    Mar 17th
    13 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    16 Files
  • 21
    Mar 21st
    13 Files
  • 22
    Mar 22nd
    5 Files
  • 23
    Mar 23rd
    6 Files
  • 24
    Mar 24th
    47 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    50 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    7 Files
  • 30
    Mar 30th
    31 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close