 
Bugtraq mailing list archives
Re: ISS Security Advisory: Backdoor Password in Red Hat Linux Virtual Server Package
From: gafton () REDHAT COM (Cristian Gafton)
Date: Tue, 25 Apr 2000 18:29:54 -0400
On Tue, 25 Apr 2000, Aleph One wrote:
Backdoor Password in Red Hat Linux Virtual Server Package
As probably it is clear by now, this is not a backdoor. The advisory refers to the *default password* for a service and by any common sense standards this does not fit the definition of a backdoor.
Impact: With this backdoor password, an attacker could compromise the web server as well as deface and destroy the web site.
Now, wait a minute. How flashy can an advisory be made? Granted the security problem is serious (I do not dispute that), but how does this implies that one has immediate access to deface a web site?! The web server runs as nobody, and I have yet to hear of sane installations that have the .html files owned by nobody. The remote users can get a shell access on a web server. *That* is the serious security vulnerability. Whatever the attacker can do from there on is a matter of the internal security on a web server. But just having this shell does not guarantee the destruction of a web site, as the ISS advisory seems to imply. Cristian -- ---------------------------------------------------------------------- Cristian Gafton -- gafton () redhat com -- Red Hat, Inc. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ "How could this be a problem in a country where we have Intel and Microsoft?" --Al Gore on Y2K
Current thread:
- FreeBSD Security Advisory: FreeBSD-SA-00:15.imap-uw, (continued)
- FreeBSD Security Advisory: FreeBSD-SA-00:15.imap-uw FreeBSD Security Officer (Apr 24)
- piranha default password/exploit Max Vision (Apr 24)
- Re: piranha default password/exploit Cristian Gafton (Apr 25)
- Re: piranha default password/exploit CDI (Apr 25)
- Re: piranha default password/exploit Matt Wilson (Apr 26)
- fingerd Psarras Nikos (Apr 27)
- Re: fingerd Brock Sides (Apr 27)
- Re: fingerd Jeremy Rauch (Apr 27)
 
- Cartfix Secret Backdoor Patch tool for cart32 Weld Pond (Apr 27)
 
 
- ISS Security Advisory: Backdoor Password in Red Hat Linux Virtual Server Package Aleph One (Apr 25)
- Re: ISS Security Advisory: Backdoor Password in Red Hat Linux Virtual Server Package Cristian Gafton (Apr 25)
 


