Re: [Security-Discuss] Exploits
[email protected] (Simon Oosthoek) Mon, 3 Apr 2006 23:43:14 +0200
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Apr 03, 2006 at 04:24:29PM -0400, Bob Puff@NLE wrote: > Hi Guys, > > Looks like one of my (fully-patched) 9.2 boxes just got rooted by two > things that I thought had been fixed a long time ago. > > It appears that they got in via the openssl-too-open exploit, and then used > a ptrace exploit to get root. > > Could someone please confirm if these 9.2 modules are indeed vulnerable (as > the advisorys seem to indicate that everything was fixed, but...): > > openssl-0.9.7b-5.1.92mdk > libopenssl0.9.7-devel-0.9.7b-5.1.92mdk > libopenssl0.9.7-0.9.7b-5.1.92mdk > kernel-2.4.22.32mdk-1-1mdk > > I was alerted to this attack by seeing net-pf-14 errors in my logs. Logged > in to see that I couldn't restart apache. I saw this running on port 80: > # lsof -i:80 > COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME > ptrace24 5251 apache 4u IPv4 137712543 TCP *:http (LISTEN) > hatori 5299 apache 4u IPv4 137712543 TCP *:http (LISTEN) > CROND 5599 apache 4u IPv4 137712543 TCP *:http (LISTEN) > > Can't seem to find ptrace24, CROND, or hatori, but they were running. > Example: > # ps ax | grep CRON > 19263 ? S 0:00 ./CROND > > I changed the SSL config to: SSLCipherSuite > ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:!SSLv2:+EXP:+eNULL > ...hoping that fixes the way they got in. > > Any ideas on fixing the ability to run the ptrace exploit? > Bob, I hate to break it to you, but AFAIK, 9.2 has been out of support for a long time. If you want a secure system, you need to run 2006.0. Or for a server, I can recommend (whispering: debian stable). Of course you can get Mandriva corporate server edition or something, that's also supported for 5 years I think, but it will not be free. The message is: use a release that still gets security updates or you will be at high risk to get hit by old exploits. Cheers Simon ____________________________________________________ Want to buy your Pack or Services from Mandriva? Go to http://store.mandriva.com Join the Club : http://www.mandrivaclub.com ____________________________________________________