vendor:
invscout
by:
ri0t
7.5
CVSS
HIGH
invscout bug
CWE
Product Name: invscout
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2005
r00t exploit for invscout bug
This exploit takes advantage of the invscout bug reported by Idefense labs. It allows an attacker to gain root access by exploiting a vulnerability in the invscout software. The exploit script automates the process of gaining root access. The exploit involves copying the ksh binary to /tmp, changing its ownership to root:system, giving it execute and setuid permissions, and then executing it. This allows the attacker to gain root access. The exploit was coded by ri0t and can be found on www.ri0tnet.net.
Mitigation:
The invscout bug has been fixed in later versions of the software. It is recommended to update to the latest version to mitigate this vulnerability.