COMMAND
aspppd
SYSTEMS AFFECTED
Solaris 2.5 x86
PROBLEM
Its relatively simple, in /tmp/ lies .asppp.fifo which is world
r/w if aspppd isnt running you simply ln -s /.rhosts
/tmp/.asppp.fifo, when root executes aspppd, /.rhosts is opened
r/w as a fifo, the second aspppd dies /.rhosts becomes a normal
file world r/w. Credit for this discovery of this vulnerability
goes to Thamer Al-Herbish <shadows@whitefang.com>