Bugtraq mailing list archives
Re: Exploit for Linux wu.ftpd hole
From: mengel () dcdmwm fnal gov (Marc W. Mengel)
Date: Thu, 6 Jul 1995 09:12:33 -0600
In <Pine.LNX.3.91.950705175939.1572B-100000 () phoenix org> you write:
There also apepars to be a bug in syslog. If you do something like: grep -v "ROOT" messages > mmm; mv mmm messages Logging is disabled, I suspect this problem is that the file pointer maintained by syslog is getting ahead of the physical EOF, and thus writes will fail, but this is just a guess, and I havent looked at the source to linux's syslog.
Actually, that sounds like Broken As Designed -- syslogd continues writing on the (unlinked) old messages file until someone sends him a SIGHUP and he rereads the config file and reopens the output files. This is really a filesystem issue and not a syslogd issue, you can remove the last directory link to any open file, and the program(s) that have it open don't notice, and the file doesn't go away 'till it's closed. Of course, the fun thing is that output file continues to fill up the filesystem with syslog messages that no-one can see... Perhaps syslogd should fstat() the file descriptor , and stat() the file name, and make sure they're the same inode, etc. periodically? Nah, even if you did make it that smart, you could still just overwrite the logfile, replacing the su/ROOT/login/ftp/whatever messages with something innocuous of the same length, and let it keep on logging... Once someone gets in there's really nothing to prevent the person from "fixing" all the logfiles to make it look like they weren't there. Of course, the paper DecWriter console won't reverse linefeed :-). Marc
Current thread:
- Exploit for Linux wu.ftpd hole Henri Karrenbeld (Jul 05)
- Re: Exploit for Linux wu.ftpd hole Mike Edulla (Jul 05)
- Re: Exploit for Linux wu.ftpd hole Karl Strickland (Jul 05)
- Re: Exploit for Linux wu.ftpd hole Larry Kruper (Jul 05)
- Re: Exploit for Linux wu.ftpd hole Mike Edulla (Jul 08)
- Re: Exploit for Linux wu.ftpd hole Timothy Newsham (Jul 05)
- Linux FIOSETOWN ioctl hole Marek Michalkiewicz (Jul 06)
- Re: Exploit for Linux wu.ftpd hole Darren Reed (Jul 06)
- Re: Exploit for Linux wu.ftpd hole Marc W. Mengel (Jul 06)
- Re: Exploit for Linux wu.ftpd hole Mike Edulla (Jul 08)
- web site Aleph One (Jul 07)
- Jul 9 08:06:03 all inetd[122]: httpd/tcp server failing Dr. Frederick B. Cohen (Jul 09)
- Re: Jul 9 08:06:03 all inetd[122]: httpd/tcp server failing Darren Reed (Jul 09)
- updated-secure-w#-daemons Dr. Frederick B. Cohen (Jul 09)
- Re: Jul 9 08:06:03 all inetd[122]: httpd/tcp server failing Kent Fitch (Jul 09)
- Re: Jul 9 08:06:03 all inetd[122]: httpd/tcp server failing Casper Dik (Jul 10)
- Re: Jul 9 08:06:03 all inetd[122]: httpd/tcp server failing Ken Wilcox (Jul 11)
- Exploit+fix for Linux SIGURG Marek Michalkiewicz (Jul 11)
- The FTP Bounce Attack *Hobbit* (Jul 11)
- Re: Exploit for Linux wu.ftpd hole Mike Edulla (Jul 05)