atom feed200 messages in org.freebsd.freebsd-securityRe: security hole in FreeBSD
FromSent OnAttachments
1 earlier message
Nicole H.Jul 28, 1997 3:22 am 
Vincent PoyJul 28, 1997 4:39 am 
Robert WatsonJul 28, 1997 5:36 am 
Nicole H.Jul 28, 1997 5:40 am 
Eric FeillantJul 28, 1997 5:41 am 
David HollandJul 28, 1997 6:12 am 
Nicole H.Jul 28, 1997 6:15 am 
Jonathan A. ZdziarskiJul 28, 1997 6:22 am 
Tomasz DudziakJul 28, 1997 6:29 am 
Adam ShostackJul 28, 1997 6:39 am 
Guido van RooijJul 28, 1997 6:52 am 
Garrett WollmanJul 28, 1997 7:04 am 
Robert WatsonJul 28, 1997 7:56 am 
Robert WatsonJul 28, 1997 7:59 am 
Ollivier RobertJul 28, 1997 8:16 am 
Robert WatsonJul 28, 1997 8:48 am 
Jonathan A. ZdziarskiJul 28, 1997 8:50 am 
Jonathan A. ZdziarskiJul 28, 1997 8:54 am 
Rodney W. GrimesJul 28, 1997 8:55 am 
Adam ShostackJul 28, 1997 9:04 am 
Robert WatsonJul 28, 1997 10:08 am 
Rodney W. GrimesJul 28, 1997 10:26 am 
Vincent PoyJul 28, 1997 10:59 am 
Vincent PoyJul 28, 1997 11:23 am 
Vincent PoyJul 28, 1997 11:27 am 
David LangfordJul 28, 1997 11:30 am 
Vincent PoyJul 28, 1997 11:31 am 
Robert WatsonJul 28, 1997 11:33 am 
Robert WatsonJul 28, 1997 11:44 am 
Jonathan A. ZdziarskiJul 28, 1997 11:46 am 
Jonathan A. ZdziarskiJul 28, 1997 11:48 am 
Jonathan A. ZdziarskiJul 28, 1997 11:49 am 
Robert WatsonJul 28, 1997 12:29 pm 
Vincent PoyJul 28, 1997 12:29 pm 
Vincent PoyJul 28, 1997 12:38 pm 
Vincent PoyJul 28, 1997 12:48 pm 
Vincent PoyJul 28, 1997 12:54 pm 
Vincent PoyJul 28, 1997 12:56 pm 
Adam ShostackJul 28, 1997 1:04 pm 
Jonathan A. ZdziarskiJul 28, 1997 1:15 pm 
Jonathan A. ZdziarskiJul 28, 1997 1:16 pm 
Robert WatsonJul 28, 1997 1:45 pm 
Jonathan A. ZdziarskiJul 28, 1997 1:47 pm 
Jonathan A. ZdziarskiJul 28, 1997 1:51 pm 
Robert WatsonJul 28, 1997 1:54 pm 
Nate WilliamsJul 28, 1997 2:00 pm 
Ollivier RobertJul 28, 1997 2:07 pm 
Matthew N. DoddJul 28, 1997 2:14 pm 
Karl DenningerJul 28, 1997 2:42 pm 
Vincent PoyJul 28, 1997 2:43 pm 
Vincent PoyJul 28, 1997 3:01 pm 
Vincent PoyJul 28, 1997 3:06 pm 
Jordan K. HubbardJul 28, 1997 3:10 pm 
Vincent PoyJul 28, 1997 3:25 pm 
Vincent PoyJul 28, 1997 3:28 pm 
Matthew N. DoddJul 28, 1997 3:30 pm 
Vincent PoyJul 28, 1997 3:30 pm 
Vincent PoyJul 28, 1997 3:44 pm 
Brian BuchananJul 28, 1997 4:06 pm 
Gary Clark IIJul 28, 1997 4:06 pm 
Vincent PoyJul 28, 1997 4:14 pm 
Vincent PoyJul 28, 1997 4:16 pm 
Vincent PoyJul 28, 1997 4:18 pm 
Matthew N. DoddJul 28, 1997 4:18 pm 
Vincent PoyJul 28, 1997 4:19 pm 
Vincent PoyJul 28, 1997 4:25 pm 
Vincent PoyJul 28, 1997 4:30 pm 
Brian BuchananJul 28, 1997 4:48 pm 
Jordan K. HubbardJul 28, 1997 4:59 pm 
Jordan K. HubbardJul 28, 1997 5:00 pm 
Vincent PoyJul 28, 1997 5:02 pm 
Brian BuchananJul 28, 1997 5:09 pm 
Vincent PoyJul 28, 1997 5:19 pm 
Vincent PoyJul 28, 1997 5:20 pm 
Gary PalmerJul 28, 1997 5:22 pm 
Vincent PoyJul 28, 1997 5:26 pm 
Vincent PoyJul 28, 1997 5:30 pm 
Gary PalmerJul 28, 1997 5:30 pm 
Brian BuchananJul 28, 1997 5:32 pm 
Gary PalmerJul 28, 1997 5:33 pm 
Vincent PoyJul 28, 1997 5:34 pm 
Gary PalmerJul 28, 1997 5:36 pm 
Vincent PoyJul 28, 1997 5:40 pm 
Gary PalmerJul 28, 1997 5:44 pm 
Gary PalmerJul 28, 1997 5:45 pm 
Vincent PoyJul 28, 1997 5:49 pm 
Gary PalmerJul 28, 1997 5:53 pm 
Vincent PoyJul 28, 1997 5:57 pm 
Vincent PoyJul 28, 1997 6:01 pm 
Vincent PoyJul 28, 1997 6:01 pm 
Brian BuchananJul 28, 1997 6:19 pm 
Brian BuchananJul 28, 1997 6:24 pm 
Matthew N. DoddJul 28, 1997 6:41 pm 
Robert WatsonJul 28, 1997 6:59 pm 
Robert WatsonJul 28, 1997 7:00 pm 
Vincent PoyJul 28, 1997 7:01 pm 
Vincent PoyJul 28, 1997 7:04 pm 
Matthew N. DoddJul 28, 1997 7:19 pm 
John PreislerJul 28, 1997 7:31 pm 
Brian BuchananJul 28, 1997 7:52 pm 
99 later messages
Subject:Re: security hole in FreeBSD
From:Vincent Poy (vin@mail.MCESTATE.COM)
Date:Jul 28, 1997 2:43:53 pm
List:org.freebsd.freebsd-security

On Mon, 28 Jul 1997, [Mario1-] wrote:

=)On Mon, 28 Jul 1997, Jonathan A. Zdziarski wrote: =) =): There IS one common hole I've seen apache and stronghold have, and that is =): that some people like to leave their sessiond or httpd files owned by =): 'nobody'. This allows somebody running CGI on that system to replace =): those binaries with their own, hacked binaries (since the scripts are =): usually owned as nobody), and the next time httpd starts, they can make it =): write a root shell, or just about anything along those lines. =) =)Now THIS is interesting. I was thinking about this a little while ago. =)Didn't it seem like 'nobody' had an awful lot of processes running =)last night?

Yes, it did but they were all httpd and I understand apache httpd has fixed this security hole a long time ago since we are using the new version of apache.

Cheers, Vince - vin@MCESTATE.COM - vin@GAIANET.NET ________ __ ____ Unix Networking Operations - FreeBSD-Real Unix for Free / / / / | / |[__ ] GaiaNet Corporation - M & C Estate / / / / | / | __] ] Beverly Hills, California USA 90210 / / / / / |/ / | __] ] HongKong Stars/Gravis UltraSound Mailing Lists Admin /_/_/_/_/|___/|_|[____]