Re: RAZOR advisory: Linux util-linux chfn local root vulnerability

From: Michal Zalewski (lcamtufat_private)
Date: Tue Jul 30 2002 - 06:59:36 PDT

  • Next message: Andrew Pimlott: "Re: RAZOR advisory: Linux util-linux chfn local root vulnerability"

    On Tue, 30 Jul 2002, Andrew Pimlott wrote:
    
    > If he is smart, he will check whether the file is open (eg with fuser)
    > before removing it.  So your attack does require an administrator
    > mistake.
    
    Not really. The file does not have to be open to be present in the system.
    It is prefectly possible to leave a dangling root-owned file several
    times, so that the administrator can do very little to determine where it
    came from. The attack itself requires the file to be open, but it can
    happen long after the administor started removing this file routinely.
    
    > However!  There appears to be an attack that does not require any
    > administrator action.
    
    Appears to be true, good point.
    
    -- 
    _____________________________________________________
    Michal Zalewski [lcamtufat_private] [security]
    [http://lcamtuf.coredump.cx] <=-=> bash$ :(){ :|:&};:
    =-=> Did you know that clones never use mirrors? <=-=
              http://lcamtuf.coredump.cx/photo/
    



    This archive was generated by hypermail 2b30 : Tue Jul 30 2002 - 14:53:10 PDT