Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The actual release from Pure Hacking is here:

http://www.purehacking.com/blogs/gordon-maddern/skype-0day-v...

No mention of root; only remote shell. I have a feeling this is just bad reporting on the part of The Register.

Having said that, I wouldn't give a random person off the street access to my local user account, even if they can't execute as root. Plenty of attackers would be content to rsync all your files to their server for further examination/exploitation.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: