Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: another /usr/dt/bin/dtappgather feature!

Re: another /usr/dt/bin/dtappgather feature!

From: Casper Dik <casper_at_HOLLAND.SUN.COM>
Date: Mon, 9 Nov 1998 20:44:12 +0100

> The problem with DTUSERSESSION was already posted on last
> Feb 24; and by then, the "Solaris dtappgather patch" fixed the
> DTUSERSESSION but not the link (directory permissions) problem,
> which probably is fixed by the other patch on 2.5.x.
>
> So, at least Solaris 2.6 (sparc) with recent patches is not
> vulnerable.

The problem is patched with both the dtappgather and dtlogin
patches to Solaris 2.5.1/2.6 (and presumably 2.5 as well).

You need to apply both and restart dtlogin.

I'm not sure, but you might even need to rm -rf /var/dt before restarting
dtlogin, but it seems it will fix up the permissions on startup.

Casper
Received on Nov 09 1998

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]