3 ms·
This is only a vulnerability if you don't know what ldd does. The problem is that it's not necessarily easy to find out what ldd does. The man pages for Solar
by thirdstation 17y ago
This is only a vulnerability if you don't know what ldd does. The problem is that it's not necessarily easy to find out what ldd does.
The man pages for Solaris 8-10 will tell you not to run it on untrusted files. But, if you Google "man ldd" you may get this page (the first result for me, btw):
http://unixhelp.ed.ac.uk/CGI/man-cgi?ldd+1 http://unixhelp.ed.ac.uk/CGI/man-cgi?ldd+1
Which is very sparse. If you are not an experienced SA you may not notice that the information is old, or not applicable to your platform. There are a lot of quasi-administrators (techy folk in your dept. w/ admin privileges) who may be vulnerable to social engineering by a consultant or evil employee (I've seen both happen).
We are all vulnerable to what we don't know.
- derobert 17y agoThat link is actually the current one on my Debian testing/Squeeze system. Its part of at least reasonably current glibc releases.