|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Solaris patchadd(1) (3) symlink vulnerabilty
From: Juergen P. Meier (jpm
CLASS.DE)Date: Thu Dec 21 2000 - 05:09:31 CST
- Next message: Martin Rex: "Re: "The End of SSL and SSH?""
- Previous message: Kuznetsov, Vasily: "Re: Oracle WebDb engine brain-damagse"
- In reply to: Paul Szabo: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Next in thread: Paul Theodoropoulos: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Next in thread: Juan M. Courcoul: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Juergen P. Meier: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Paul Theodoropoulos: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Thu, Dec 21, 2000 at 09:13:29AM +1100, Paul Szabo wrote:
> Juergen P. Meier <jpm
class.de> wrote:
>
> > Solaris /usr/sbin/patchadd is a /bin/ksh script.
> > The problem lies in the vulnerability of ksh.
>
> Damn: thus it would seem that not only sh, but also ksh is vulnerable!
seems so :(
> > However: Sun Microsystems does recommend to only install
> > patches at single-user mode (runlevel S). ...
> > ... if you follow the Vendors recommendations, you are
> > not vulnerable.
>
> The attacker can create the symlinks before you go single-user. As the
> original poster Jonathan Fortin <jfortin
REVELEX.COM> said:
>
> > Only solution is to rm -rf /tmp/* /tmp/.* [and] make sure no users are on
>
> Paul Szabo - psz
maths.usyd.edu.au http://www.maths.usyd.edu.au:8000/u/psz/
> School of Mathematics and Statistics University of Sydney 2006 Australia
I do indeed stand corrected: The only 2 sollutions are:
1) change to single user mode by means of init S
and rm -rf /tmp/* /tmp/.*
2) shutdown and boot -s into single user mode.
you should do this at least once (when sun releases the shell-patches ;)
have a nice day,
Juergen
-- Juergen P. Meier email: jpmclass.de
- Next message: Martin Rex: "Re: "The End of SSL and SSH?""
- Previous message: Kuznetsov, Vasily: "Re: Oracle WebDb engine brain-damagse"
- In reply to: Paul Szabo: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Next in thread: Paul Theodoropoulos: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Next in thread: Juan M. Courcoul: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Juergen P. Meier: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Reply: Paul Theodoropoulos: "Re: Solaris patchadd(1) (3) symlink vulnerabilty"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]