Skip to content

suidroot plugin makes invalid assumptions #105

@nil0x42

Description

@nil0x42

The suidroot plugin checks in payload.php if the file has SUID bit set before execution.
Therefore, in a context where open_basedir restriction doesn't allow to read SUIDROOT_BACKDOOR, the plugin will leave with an error message while the backdoor could in reality be executed..

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions