Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: SengirV
Nothing to see here folks, move along.

I wish, but this is a nasty hole. Because it's trusted by default, the LDAP server can specify mountpoints on your box, which means I can run any arbitrary code I like by mounting my filesystem overtop yours. I can set up a root crontab job that starts up my code automatically, like enabling SSH, even if you've disabled it, and at that point, I've got a root login available to me, even if you don't - and odds are, you'd never notice what I was up to. All I have to do is sit back and wait for you to reboot to take my configuration instead of yours.

47 posted on 11/26/2003 7:57:05 PM PST by general_re (Take away the elements in order of apparent non-importance.)
[ Post Reply | Private Reply | To 40 | View Replies ]


To: general_re
So in order to exploit this, you must have total control over my network, since you are replacing the existing LDAP server. Yes it is a problem, but far from the usual windows problems where opening up an email totally screws you over.
52 posted on 11/26/2003 9:04:33 PM PST by SengirV
[ Post Reply | Private Reply | To 47 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson