[16355] in bugtraq
Re: RH 6.1 / 6.2 minicom vulnerability
daemon@ATHENA.MIT.EDU (Ben Lull)
Tue Aug 22 18:23:52 2000
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-Id:  <39A2D8E7.AC296DCB@valleylocal.com>
Date:         Tue, 22 Aug 2000 12:47:51 -0700
Reply-To: blull@valleylocal.com
From: Ben Lull <blull@VALLEYLOCAL.COM>
To: BUGTRAQ@SECURITYFOCUS.COM
Slackware 7.0 (minicom 1.82):
    plix@technolust:/home/plix> groups
    secure wheel xuser plix
    plix@technolust:/home/plix> minicom -C foo
    minicom: cannot open /dev/ttyS1: Permission denied
    plix@technolust:/home/plix> ls -al foo
    -rw-r--r--   1 plix     uucp            0 Aug 22 12:36 foo
    plix@technolust:/home/plix>
Slackware 7.1 (minicom 1.82.1)
    plix@mos:/home/plix> groups
    users
    plix@mos:/home/plix> minicom -C foo
    minicom: cannot open /dev/ttyS1: Permission denied
    plix@mos:/home/plix> ls -al foo
    -rw-r--r--   1 plix     uucp            0 Aug 22 12:39 foo
-- Yep Slackware too using minicom 1.82 and 1.82.1
Thanks,
Ben Lull
***
* Ben Lull
* Valley Local Internet, Inc.
* Systems Administrator
***
Michal Zalewski wrote:
> On RedHat 6.1 and RedHat 6.2 boxes (I haven't found other
distributions
> vulnerable):
>
> @(#)Minicom V1.83.0 (compiled Mar  7 2000)(c) Miquel van Smoorenburg
>
> [lcamtuf@nimue lcamtuf]$ minicom -C foo
> minicom: there is no global configuration file /etc/minirc.dfl
> Ask your sysadm to create one (with minicom -s).
>
> [lcamtuf@nimue lcamtuf]$ ls -l foo
> -rw-rw-r--   1 lcamtuf  uucp            0 Aug 18 12:21 foo
>     ^^                  ^^^^
>
> Any file can be created anywhere with uucp privledges - it will follow
> symlinks. Not nice on systems running uucp services.
>
> _______________________________________________________
> Michal Zalewski [lcamtuf@tpi.pl] [tp.internet/security]
> [http://lcamtuf.na.export.pl] <=--=> bash$ :(){ :|:&};:
> =-----=> God is real, unless declared integer. <=-----=
>
> -- Support your government, give Echelon / Carnivore something to
parse --
> classfield  top-secret government  restricted data information project
CIA
> KGB GRU DISA  DoD  defense  systems  military  systems spy steal
terrorist
> Allah Natasha  Gregori destroy destruct attack  democracy will send
Russia
> bank system compromise international  own  rule the world ATSC RTEM
warmod
> ATMD force power enforce  sensitive  directorate  TSP NSTD ORD DD2-N
AMTAS
> STRAP warrior-T presidental  elections  policital foreign embassy
takeover
>
--------------------------------------------------------------------------