New User, Welcome!     Login

Next Page >>

University of Sydney

Mathematica8 on Linux /tmp/MathLink vulnerability

also/still in (the "free trial" version of) Mathematica8.

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia


---

I wrote on 14 May 2010:

Mathematica8.0.4 on Linux /tmp/MathLink vulnerability

present for the command-line interface "math" also.

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia


---

http://lists.grok.org.uk/pipermail/full-disclosure/2010-May/074548.html

Re: /proc filesystem allows bypassing directory permissions on Linux

How would you do that? Cannot use fcntl() as that would not let you.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on

dangerous, or common, or conducive to mayhem: no urgency to fix.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

> Sorry to blow your assumption: sent to Oracle, ages ago, first thing.
>
> Cheers, Paul
>
> Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
> School of Mathematics and Statistics   University of Sydney    Australia
>



Re: Mathematica8.0.4 on Linux /tmp/MathLink vulnerability

> present for the command-line interface "math" also.
>
> Cheers,
>
> Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
> School of Mathematics and Statistics   University of Sydney    Australia
>
>
> ---
>
> http://lists.grok.org.uk/pipermail/full-disclosure/2010-May/074548.html

Re: Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability

can be better exploited.

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Mathematica8.0.4 on Linux /tmp/MathLink vulnerability

Wolfram.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



RE: Samba Remote Zero-Day Exploit

extensions" (which I had set to non-default "no" to help Mac clients).

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

"originally gs" or "Debian special".

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Yes, but... seems not all echo's get a Referer passed to them.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

They seem to have a strong pro-Windows, contra-Linux stance.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

Do not lower security, just to emulate /proc sloppiness. (That would be
like fixing a root security bug by doing away with the root password.)
Is there anything (currently) relying on that security?

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

Yes, precisely: that is why I called it any.ps.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Samba Remote Zero-Day Exploit

> No please, do not dumb it down.
> 
> Cheers, Paul
> 
> Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
> School of Mathematics and Statistics   University of Sydney    Australia




Re: [Full-disclosure] Samba Remote Zero-Day Exploit

pssea> Cheers, Paul

pssea> Paul Szabo   psz@maths.usyd.edu.au  
pssea> http://www.maths.usyd.edu.au/u/psz/
pssea> School of Mathematics and Statistics   University of Sydney    Australia

pssea> _______________________________________________
pssea> Full-Disclosure - We believe in it.
pssea> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
pssea> Hosted and sponsored by Secunia - http://secunia.com/

Re: /proc filesystem allows bypassing directory permissions on Linux

> How would you do that? Cannot use fcntl() as that would not let you.
>
> Cheers, Paul
>
> Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
> School of Mathematics and Statistics   University of Sydney     
> Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

"upgrade" that to O_RDWR.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Sorry to blow your assumption: sent to Oracle, ages ago, first thing.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

matter for debate (by opinionated people) is whether it should be fixed.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Samba Remote Zero-Day Exploit

No please, do not dumb it down.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: [Full-disclosure] Samba Remote Zero-Day Exploit

Is that vendor Samba?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



/bin/login DoS remains after DSA-1709

know about other distros.)

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on

himself in the foot).

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Samba Remote Zero-Day Exploit

extensions" (which I had set to non-default "no" to help Mac clients).

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Were not those obvious to right-thinking people?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Samba Remote Zero-Day Exploit

servers (as I do, see http://www.maths.usyd.edu.au/u/psz/samba/).

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

where openat() succeeds without permissions?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



/bin/login gives root to group utmp

leveraged to get root).

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

a proof-of-concept demo?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!