|
|
|
|
|
by thrownaway2424
4450 days ago
|
|
This isn't a root exploit. It serves up files that are readable by the serving process, such as /etc/passwd. You are aware, I hope because it's been this way for 20+ years, that despite the name there are no passwords in /etc/passwd, right? It's not considered a sensitive file. % ls -l /etc/passwd
-rw-r--r-- 1 root root 2028 Dec 2 13:05 /etc/passwd
|
|
Your posts are exactly the kind of thing I _want_ to read on HN. Is there a particular reason why you feel you can't post this under a general-use account?