|
|
[ Message Precedent sur la mailing][ Message Suivant sur la mailing][ Precedent dans le fil][ Prochain dans le fil][ Index par Date][ Index par fil]
Re: [Full-disclosure] Samba Remote Zero-Day Exploit
Hi Paul,
Facts :
- Several distributions run with vulnerable settings per default
if there is a "misconfiguration" it is part of the vendor.
- Your not supposed to be able to traverse dirs.
Consequence it is a vulnerability, whether you can mitigate it is
a different piece of cake.
Next time somebody creates an IE8 0day that relies on javascript,
will you scream "misconfiguration!" ? Of course you could disable
javascript but is it by enabled default ? Yes.
The question for smb is who does restrict this setting?
My tests reveal - not many.
Congrats Kingcope, nice bug. Directory traversal in major daemon in
2010.
Regards,
Thierry
pssea> Dear Kingcope,
pssea> The samba server follows symlinks by default. There are options
pssea> ("follow symlinks", "wide links") for turning it off:
pssea> link://[click]
pssea> link://[click]
pssea> link://[click]
pssea> The "problem" at your installation seems a mis-configuration of
pssea> your server: please ask the admin to set "secure" options.
pssea> (Some samba installations, like mine, wish to allow same access as a
pssea> UNIX login would allow. Some shares like [home] are provided for ease
pssea> of use, users are encouraged to create symlinks to other "interesting"
pssea> places e.g. NFS-mounted directories.)
pssea> Cheers, Paul
pssea> Paul Szabo psz@xxxxxxxxxxxxxxxxx
pssea> link://[click]
pssea> School of Mathematics and Statistics University of Sydney Australia
pssea>
pssea> Full-Disclosure - We believe in it.
pssea> Charter: link://[click]
pssea> Hosted and sponsored by Secunia - link://[click]
--
link://[click]
Thierry Zoller
Full-Disclosure - We believe in it.
Charter: link://[click]
Hosted and sponsored by Secunia - link://[click]
Archives de la liste de diffusion Secunia
Archives de la liste de diffusion BugTraq
Archives de la liste de diffusion DailyDave
Archives de la liste de diffusion FunSec
Archives de la liste de diffusion Full Disclosure
Archives de la liste de diffusion Focus-IDS (FD)
Archives de la liste de diffusion Webappsec (FD)
Archives de la liste de diffusion Security-basics (FD)
Archives de la liste de diffusion Vulndiscuss
Archives de la liste de diffusion Vulnwatch
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, microsoft, réseau, attaque, outil, vulnérabilité, audit, système, virus, internet, données, présentation, metasploit, linux, bluetooth, protocol, vista, scanner, réseaux, shell, engineering, rootkit, paquet, conférence, trames, wishmaster, téléphone, source, sysun, noyau, mobile, https, mémoire, rapport, botnet, téléphones, libre, reverse, navigateur, patch, snort, scapy, intel |
| Mini-Tagwall de l'annuaire video : | | | | vmware, security, virus, biometric, windows, lockpicking, password, botnet, metasploit, tutorial, attack, crypt, linux, network, iphone, server, exploit, conficker, wimax, virtu, virtual, engineering, reverse, cisco, ettercap, wireshark, shmoocon, hacker, firewall, internet, knoppix, rootkit, arduino, source, conference, wireless, backtrack, openbsd, brucon, systm, overflow, openssh, buffer, access, remote |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|