<?xml version="1.0" encoding="utf-8"?><!-- generator="wordpress/1.5.1-alpha" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: NUKIDO: Various Local Vulnerabilities in Mac OS X  10.3.x</title>
	<link>http://negative.blogsome.com/2005/01/19/nukido/</link>
	<description>Mstrbtn tchnqs shld b ncrgd nd tght n the pblc schl systms!</description>
	<pubDate>Tue, 08 Dec 2009 21:26:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=1.5.1-alpha</generator>

	<item>
		<title>by: anonymous</title>
		<link>http://negative.blogsome.com/2005/01/19/nukido/#comment-5</link>
		<pubDate>Thu, 27 Jan 2005 09:12:58 +0000</pubDate>
		<guid>http://negative.blogsome.com/2005/01/19/nukido/#comment-5</guid>
					<description>AgD, if you read carefully on &lt;a href=&quot;http://www.immunitysec.com/downloads/nukido.pdf&quot;&gt;NUKIDO&lt;/a&gt; advisory, the exploitation of &lt;em&gt;at&lt;/em&gt; will give you the content of &lt;em&gt;master.passwd&lt;/em&gt; file. But, did you understand^Wread &lt;em&gt;master.passwd&lt;/em&gt; header file? Hope you get the idea.</description>
		<content:encoded><![CDATA[	<p>AgD, if you read carefully on <a href="http://www.immunitysec.com/downloads/nukido.pdf">NUKIDO</a> advisory, the exploitation of <em>at</em> will give you the content of <em>master.passwd</em> file. But, did you understand^Wread <em>master.passwd</em> header file? Hope you get the idea.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: AgD</title>
		<link>http://negative.blogsome.com/2005/01/19/nukido/#comment-4</link>
		<pubDate>Thu, 27 Jan 2005 08:34:05 +0000</pubDate>
		<guid>http://negative.blogsome.com/2005/01/19/nukido/#comment-4</guid>
					<description>/etc/master.passwd

Last login: Thu Jan 27 15:32:30 on ttyp2
Welcome to Darwin!
G4x:~ agd$ cd /etc
G4x:/etc agd$ sudo vi master.passwd
Password:


##
# User Database
#
# Note that this file is consulted when the system is running in single-user
# mode.  At other times this information is handled by lookupd.  By default,
# lookupd gets information from NetInfo, so this file will not be consulted
# unless you have changed lookupd's configuration.
##
nobody:*:-2:-2::0:0:Unprivileged User:/var/empty:/usr/bin/false
root:*:0:0::0:0:System Administrator:/var/root:/bin/sh
daemon:*:1:1::0:0:System Services:/var/root:/usr/bin/false
:
.
cyrus:*:77:6::0:0:Cyrus User:/var/imap:/usr/bin/false
mailman:*:78:78::0:0:Mailman user:/var/empty:/usr/bin/false
appserver:*:79:79::0:0:Application Server:/var/empty:/usr/bin/false
&quot;master.passwd&quot; 23L, 1259C

whats wrong?!</description>
		<content:encoded><![CDATA[	<p>/etc/master.passwd</p>
	<p>Last login: Thu Jan 27 15:32:30 on ttyp2<br />
Welcome to Darwin!<br />
G4x:~ agd$ cd /etc<br />
G4x:/etc agd$ sudo vi master.passwd<br />
Password:</p>
	<p>##<br />
# User Database<br />
#<br />
# Note that this file is consulted when the system is running in single-user<br />
# mode.  At other times this information is handled by lookupd.  By default,<br />
# lookupd gets information from NetInfo, so this file will not be consulted<br />
# unless you have changed lookupd&#8217;s configuration.<br />
##<br />
nobody:*:-2:-2::0:0:Unprivileged User:/var/empty:/usr/bin/false<br />
root:*:0:0::0:0:System Administrator:/var/root:/bin/sh<br />
daemon:*:1:1::0:0:System Services:/var/root:/usr/bin/false<br />
:<br />
.<br />
cyrus:*:77:6::0:0:Cyrus User:/var/imap:/usr/bin/false<br />
mailman:*:78:78::0:0:Mailman user:/var/empty:/usr/bin/false<br />
appserver:*:79:79::0:0:Application Server:/var/empty:/usr/bin/false<br />
&#8220;master.passwd&#8221; 23L, 1259C</p>
	<p>whats wrong?!
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: KF</title>
		<link>http://negative.blogsome.com/2005/01/19/nukido/#comment-3</link>
		<pubDate>Thu, 27 Jan 2005 03:37:18 +0000</pubDate>
		<guid>http://negative.blogsome.com/2005/01/19/nukido/#comment-3</guid>
					<description>as a bug reporter what was your experience with apple...  I am looking for something to compare mine to. kf_lists[at]digitalmunition[dot]com
-KF</description>
		<content:encoded><![CDATA[	<p>as a bug reporter what was your experience with apple&#8230;  I am looking for something to compare mine to. kf_lists[at]digitalmunition[dot]com<br />
-KF
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: amen</title>
		<link>http://negative.blogsome.com/2005/01/19/nukido/#comment-2</link>
		<pubDate>Sat, 22 Jan 2005 18:40:03 +0000</pubDate>
		<guid>http://negative.blogsome.com/2005/01/19/nukido/#comment-2</guid>
					<description>macsux!!!
btw sepi amat dari komen, gak ada yg ngebahas roy suryo sih. coba kalo ada... kan bisa ber-hi-roy-ria</description>
		<content:encoded><![CDATA[	<p>macsux!!!<br />
btw sepi amat dari komen, gak ada yg ngebahas roy suryo sih. coba kalo ada&#8230; kan bisa ber-hi-roy-ria
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
