|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Solaris patchadd(1) (3) symlink vulnerabilty
From: Paul Szabo (psz
MATHS.USYD.EDU.AU)Date: Wed Dec 20 2000 - 16:13:29 CST
- Next message: Brett Glass: "Re: "The End of SSL and SSH?""
- Previous message: Jose Nazario: "Re: OpenBSD remote root"
- Maybe in reply to: Jonathan Fortin: "Solaris patchadd(1) (3) symlink vulnerabilty"
- Next in thread: Peter W: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Maybe reply: Paul Szabo: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Peter W: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Juergen P. Meier: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Juan M. Courcoul: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Juergen P. Meier <jpm
class.de> wrote:
> Solaris /usr/sbin/patchadd is a /bin/ksh script.
> The problem lies in the vulnerability of ksh.
Damn: thus it would seem that not only sh, but also ksh is vulnerable!
> However: Sun Microsystems does recommend to only install
> patches at single-user mode (runlevel S). ...
> ... if you follow the Vendors recommendations, you are
> not vulnerable.
The attacker can create the symlinks before you go single-user. As the
original poster Jonathan Fortin <jfortin
REVELEX.COM> said:
> Only solution is to rm -rf /tmp/* /tmp/.* [and] make sure no users are on
Paul Szabo - psz
maths.usyd.edu.au http://www.maths.usyd.edu.au:8000/u/psz/
School of Mathematics and Statistics University of Sydney 2006 Australia
- Next message: Brett Glass: "Re: "The End of SSL and SSH?""
- Previous message: Jose Nazario: "Re: OpenBSD remote root"
- Maybe in reply to: Jonathan Fortin: "Solaris patchadd(1) (3) symlink vulnerabilty"
- Next in thread: Peter W: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Maybe reply: Paul Szabo: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Peter W: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Juergen P. Meier: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Juan M. Courcoul: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]