[Security-Discuss] Exploits

"Bob Puff@NLE" <bob-6dd4Sf22++lWk0Htik3J/[email protected]> Mon, 03 Apr 2006 16:24:29 -0400
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
Hi Guys,

Looks like one of my (fully-patched) 9.2 boxes just got rooted by two things that I thought had been 
fixed a long time ago.

It appears that they got in via the openssl-too-open exploit, and then used a ptrace exploit to get 
root.

Could someone please confirm if these 9.2 modules are indeed vulnerable (as the advisorys seem to 
indicate that everything was fixed, but...):

openssl-0.9.7b-5.1.92mdk
libopenssl0.9.7-devel-0.9.7b-5.1.92mdk
libopenssl0.9.7-0.9.7b-5.1.92mdk
kernel-2.4.22.32mdk-1-1mdk

I was alerted to this attack by seeing net-pf-14 errors in my logs.  Logged in to see that I 
couldn't restart apache.  I saw this running on port 80:
# lsof -i:80
COMMAND   PID   USER   FD   TYPE    DEVICE SIZE NODE NAME
ptrace24 5251 apache    4u  IPv4 137712543       TCP *:http (LISTEN)
hatori   5299 apache    4u  IPv4 137712543       TCP *:http (LISTEN)
CROND    5599 apache    4u  IPv4 137712543       TCP *:http (LISTEN)

Can't seem to find ptrace24, CROND, or hatori, but they were running.
Example:
# ps ax | grep CRON
19263 ?        S      0:00 ./CROND

I changed the SSL config to: SSLCipherSuite 
ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:!SSLv2:+EXP:+eNULL
...hoping that fixes the way they got in.

Any ideas on fixing the ability to run the ptrace exploit?

Bob

I changed the +




____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________