[5361] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: RedHat4.0 security

daemon@ATHENA.MIT.EDU (Wes Parker)
Wed Nov 20 22:24:28 1996

To: redhat-list@redhat.com
Cc: chris@ferret.lmh.ox.ac.uk
In-Reply-To: Your message of "Thu, 21 Nov 1996 02:43:29 GMT."
             <Pine.LNX.3.91.961121023253.660B-100000@ferret.lmh.ox.ac.uk> 
Date: Wed, 20 Nov 1996 22:19:19 -0500
From: Wes Parker <wesp@ennui.ioa.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com

--==!Exmh_1618593876P
Content-Type: message/rfc822

X-Mailer: exmh version 1.6.9 8/22/96
To: redhat-list@redhat.com
Cc:chris@ferret.lmh.ox.ac.uk
Subject: Re: RedHat4.0 security 
In-Reply-To: Your message of "Thu, 21 Nov 1996 02:43:29 GMT."
             <Pine.LNX.3.91.961121023253.660B-100000@ferret.lmh.ox.ac.uk> 
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii

Chris--
:  Hi,
:  
:  On my redhat4.0 system, a "find / -perm 4000" lists an awful lot of suid
:  programs. Some sound highly dubious. How many of these have been scrutinised
:  for security holes?

Tried that on my box:

[root@ennui /root]# find / -perm 4000
[root@ennui /root]# 

:  On other security issues, I'm far from impressed by the (default) 
:  permissions on log files. Are we in a situation where it could be 
:  logged publicly readable, if somone gets a failed login due to mixing 
:  password with username? Many of the somewhat more security-oriented 
:  config files could do with a permissions rethink too. I don't want normal 
:  users browsing my setup. Look at it another way: there's no _valid need_ 
:  for them to be able to read them.

You're right about the log files if I'm an ISP or in an environment with a 
large number of users. When I'm on my box at home I don't particularly want to 
have to su or log into a root session to look at system logs.  Whatever the 
default, there's always "chmod" if the current perms aren't the most desirable 
for the application...
 
:  
:  Finally, there was an alert to do with the wu-ftpd shipped with redhat, a 
:  little time ago. Something to do with the realpath exploit, as well as 
:  problems with the tar --rsh-command option, if supported by the ftp tar 
:  binary...
:  

Doesn't the latest RPM fix this?

Wes
-- 
------------------------------------------------------------------
"What you seek in vain for, half your life, one day you come
 full upon, all the family at dinner.  You seek it like a dream,
 and as soon as you find it you become its prey."  - Thoreau

FINGER wesp@ioa.com for public PGP key.



--==!Exmh_1618593876P
Content-Type: application/pgp-signature

-----BEGIN PGP MESSAGE-----
Version: 2.6.2

iQCVAwUBMpPKNFheKb/OOTtZAQHwGwP/frKuTe4a9b8xxZsrYS+Trs29BmAEVbZ2
Oq2OJlaDZOKHolG6cHuP0BrQjZm+MGpdo1jC++NlY/cbIrWMWEqJtVzm3MnSCerR
YXT2kLXbIHiJEc5tUYsNiPmSwNmDxk2rsThAxYyyxnNjo8L5lMhmkbACCWyvXmXL
Jz6r8/FKT9E=
=uXqx
-----END PGP MESSAGE-----

--==!Exmh_1618593876P--


--
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
  ________________________________________________________________________
  http://www.redhat.com/RedHat-FAQ   http://www.redhat.com/RedHat-Errata
  http://www.redhat.com/RedHat-Tips  http://www.redhat.com/mailing-lists
  ------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null


home help back first fref pref prev next nref lref last post