|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: majordomo local exploit
Subject: Re: majordomo local exploit
From: Chan Wilson (cwilson
NEU.SGI.COM)
Date: Fri Jan 07 2000 - 09:27:32 CST
- Next message: Brock Tellier: "Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow"
- Previous message: Georgi Guninski: "IE 5 security vulnerablity - circumventing Cross-frame security policy and accessing the DOM of "old" documents."
- Maybe reply: Chan Wilson: "Re: majordomo local exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
> The following patch, built upon code and suggestions submitted by
> Henrik Edlund, Henrik Nordstrom, and Andrew Brown, is intended to render
> safe the config file requires, in the seven scripts which use them, in
> the Majordomo 1.94.4 home directory. It also incorporates Todd Miller's
> patch of Dec. 29.
This doesn't address the problem on Unixen that allow one to 'give
away' files. Nor is it compatible with the philosophy that majordomo
1.x should continue to run under perl4.
The proper fix appears to be simply 'chmod 0750 wrapper', perhaps
along with setting the group owner of wrapper to the same as the MTA.
And, of course, restricting access to the majordomo server.
--Chan
majordomo maintainer.
- Next message: Brock Tellier: "Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow"
- Previous message: Georgi Guninski: "IE 5 security vulnerablity - circumventing Cross-frame security policy and accessing the DOM of "old" documents."
- Maybe reply: Chan Wilson: "Re: majordomo local exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
This archive was generated by hypermail 2b27 : Fri Jan 07 2000 - 11:51:14 CST