detekce su exploitu

Ivo Panacek ivop na regionet.cz
Středa Červen 5 18:02:37 CEST 2002


Netusite nekdo, zde/kde najit nejaky (open/free) sw
na detekci (= odstraneni) tohohle exploitu?

http://vil.nai.com/vil/content/v_99394.htm

(z textu)

This code is meant for the Linux Redhat flavor.
The exploit tries to remotely access/create /tmp/xp and to changes
permissions, get root access, modifying /bin/su.
Comments inside the source indicate that the exploit was written back in
2001.

Usually Unix malware is very flavor/version/kernel specific, newer
versions and/or security updates address many exploits.

Prislusnou masinu totiz nemuzu z praktickych duvodu
ani vypnout ani reinstalovat, ... mohu k ni totiz
jenom na dalku po siti. V historicky blizke dobe ji
celou vymenim, ale ted to aktualne nejde.

Ted tam uz dlouho hledam nejruznejsi zadni vratka, lepim,
co se da.

Diky,

ivo



Další informace o konferenci Linux