OpenBSD crontab-mail(~) exploit v1.22

Vulnerability exploited: CVE-2002-0542 - BID-4495

Category: Exploits/Local

Gets root privileges in the target host.
This module exploits a vulnerability in OpenBSD crontab entries that allow arbitrary commands execution as root.To exploit the vulnerability this exploit will create a level0 agent in the target filesystem which will be automatically executed later (with root privileges) by a crontab vulnerable security entry (/etc/daily | mail). Once the level0 agent gets executed, it is possible to connect to it.If the exploit succeeds, a new level 0 will be installed with root privileges.

Supported Systems:
    OpenBSD 2.9 (i386)
    OpenBSD 3.0 (i386)


This module is included in the latest version of CORE IMPACT, the first automated comprehensive penetration testing product for accurately identifying information security risks. Click here to learn more about the product.