Re: [Security-Discuss] Exploits

[email protected] (Simon Oosthoek) Mon, 3 Apr 2006 23:43:14 +0200
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On Mon, Apr 03, 2006 at 04:24:29PM -0400, Bob Puff@NLE wrote:
> Hi Guys,
> 
> Looks like one of my (fully-patched) 9.2 boxes just got rooted by two 
> things that I thought had been fixed a long time ago.
> 
> It appears that they got in via the openssl-too-open exploit, and then used 
> a ptrace exploit to get root.
> 
> Could someone please confirm if these 9.2 modules are indeed vulnerable (as 
> the advisorys seem to indicate that everything was fixed, but...):
> 
> openssl-0.9.7b-5.1.92mdk
> libopenssl0.9.7-devel-0.9.7b-5.1.92mdk
> libopenssl0.9.7-0.9.7b-5.1.92mdk
> kernel-2.4.22.32mdk-1-1mdk
> 
> I was alerted to this attack by seeing net-pf-14 errors in my logs.  Logged 
> in to see that I couldn't restart apache.  I saw this running on port 80:
> # lsof -i:80
> COMMAND   PID   USER   FD   TYPE    DEVICE SIZE NODE NAME
> ptrace24 5251 apache    4u  IPv4 137712543       TCP *:http (LISTEN)
> hatori   5299 apache    4u  IPv4 137712543       TCP *:http (LISTEN)
> CROND    5599 apache    4u  IPv4 137712543       TCP *:http (LISTEN)
> 
> Can't seem to find ptrace24, CROND, or hatori, but they were running.
> Example:
> # ps ax | grep CRON
> 19263 ?        S      0:00 ./CROND
> 
> I changed the SSL config to: SSLCipherSuite 
> ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:!SSLv2:+EXP:+eNULL
> ...hoping that fixes the way they got in.
> 
> Any ideas on fixing the ability to run the ptrace exploit?
> 

Bob, I hate to break it to you, but AFAIK, 9.2 has been out of support
for a long time. If you want a secure system, you need to run 2006.0. Or
for a server, I can recommend (whispering: debian stable). Of course you
can get Mandriva corporate server edition or something, that's also
supported for 5 years I think, but it will not be free.

The message is: use a release that still gets security updates or you
will be at high risk to get hit by old exploits.

Cheers

Simon
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________