[ Search ]
[ What's New? ]
[ About ]
|
|
| libc-4.6.27 | |
|---|---|
| Systems Affected: | Systems using libc-4.6.27 or earlier with an entry of +::0:0::: in the password file. The NYS library seems to check for it. |
| Problem: |
To get yellow pages to work, the standard says you need to have a +::0:0:::
or a +:*:0:0::: at the end of the /etc/passwd file (I know in linux that
is not necessary, but I think most system administrators still do it
that way). The problem is that library functions getpwnam, etc, consider
'+' as a normal user, so if you have +::0:0::: in /etc/passwd, what you
really have is a passwdless root. So, as login/su don't test wether a
username begins with a +, guess what it happens?
It allows anyone to become the user, whose entry is before an entry starting with a "+" in /etc/passwd, e.g. if you have man:*:13:15:man:/usr/man: postmaster:*:14:12:postmaster:/var/spool/mail:/bin/bash ftp:*:404:1::/home/ftp:/bin/bash +@mygroup -@hackers +in /etc/passwd, then the commands su +@mygroup su -- -@hackers su +will su to ftp without a password. I contacted with the author of login (Peter Orbaek, poe@daimi.aau.dk), and he has released a new version, that tests for usernames starting with +. However I have not been able to report the bug to gnu (responsible for su) nor the maintainers of the libraries. So here goes the patch for su.c: 270a271,276 > /* If username starts with +, it is not valid, as it is the anchor for > yellow pages. Otherwise, we have a gigantic security hole. This is just > a dirty hack to fix it, as this should be fixed in the libraries instead > of programs. Feb 95. |
| Solution: | Upgrade your C library. |
|
Aleph One / aleph1@underground.org Copyright © 1996 Computer Underground Society. All rights reserved. |
|