New User, Welcome!     Login

Next Page >>

School of Mathematics and Statistics

Re: /proc filesystem allows bypassing directory permissions on Linux

> How would you do that? Cannot use fcntl() as that would not let you.
>
> Cheers, Paul
>
> Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
> School of Mathematics and Statistics   University of Sydney     
> Australia



XSS in Oracle default fcgi-bin/echo

  http://www.thisisahmed.com/tia/ohs/ohshardening.html

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

are not cached??!!

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Mathematica on Linux /tmp/MathLink vulnerability

Notified support@wolfram.com on 7 May 2010, was assigned [TS 16194].

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

"originally gs" or "Debian special".

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Mathematica8 on Linux /tmp/MathLink vulnerability

also/still in (the "free trial" version of) Mathematica8.

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia


---

I wrote on 14 May 2010:

Re: /proc filesystem allows bypassing directory permissions on Linux

> "upgrade" that to O_RDWR.
>
> Cheers, Paul
>
> Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
> School of Mathematics and Statistics   University of Sydney     
> Australia



RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Were not those obvious to right-thinking people?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

> Sorry to blow your assumption: sent to Oracle, ages ago, first thing.
>
> Cheers, Paul
>
> Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
> School of Mathematics and Statistics   University of Sydney    Australia
>



Re: [Full-disclosure] Samba Remote Zero-Day Exploit

Is that vendor Samba?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Samba Remote Zero-Day Exploit

> No please, do not dumb it down.
> 
> Cheers, Paul
> 
> Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
> School of Mathematics and Statistics   University of Sydney    Australia




Re: XSS in Oracle default fcgi-bin/echo

Maybe, contact me off-list so I can provide PoC?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: [Full-disclosure] Samba Remote Zero-Day Exploit

pssea> Cheers, Paul

pssea> Paul Szabo   psz@maths.usyd.edu.au  
pssea> http://www.maths.usyd.edu.au/u/psz/
pssea> School of Mathematics and Statistics   University of Sydney    Australia

pssea> _______________________________________________
pssea> Full-Disclosure - We believe in it.
pssea> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
pssea> Hosted and sponsored by Secunia - http://secunia.com/

Re: RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Yes, but... seems not all echo's get a Referer passed to them.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

"protection" against just ./Encoding is not enough.

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



/bin/login DoS remains after DSA-1709

know about other distros.)

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



XSS in Oracle default fcgi-bin/echo

http://download.oracle.com/docs/cd/B14099_19/core.1012/b13999/checklist.htm#BABIBCIC

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

matter for debate (by opinionated people) is whether it should be fixed.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

where openat() succeeds without permissions?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

also.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

should behave as a dup().

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

"upgrade" that to O_RDWR.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Samba Remote Zero-Day Exploit

places e.g. NFS-mounted directories.)

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on

dangerous, or common, or conducive to mayhem: no urgency to fix.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

Yes, precisely: that is why I called it any.ps.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

a proof-of-concept demo?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

How would you do that? Cannot use fcntl() as that would not let you.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



RE: Samba Remote Zero-Day Exploit

extensions" (which I had set to non-default "no" to help Mac clients).

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Sorry to blow your assumption: sent to Oracle, ages ago, first thing.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on

himself in the foot).

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!