Bugtraq mailing list archives

Re: Problem with SATAN/VMS


From: afx () ibm de (Andreas Siegert)
Date: Fri, 7 Apr 1995 23:50:55 +0200 (CEST)


SATAN on AIX has a similar problem.
AIX emits a permission denied that the simple test (test -s) doesn't catch

The bourne shell script 'rsh.satan' falsely reports a vulnerability on 
hosts that are running DEC VMS 6.1  This is because the OS sends the 
following message to standard output:

      UCX$RSHD - Permission denied - host IP addr

To fix, just add a test for the above string to the 'if $TEST -s 
"$tmp_file"' test in 'rsh.satan'.



-- 
Andreas Siegert       afx () ibm de / afx () barolo ak munich ibm com / AFX at IPNET
Every time we've moved ahead in IBM, it was because someone was willing to take
a chance, put his head on the block, and try something new - Thomas Watson, Jr.



Current thread: