home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!munnari.oz.au!cs.mu.OZ.AU!montebello.ecom.unimelb.EDU.AU!carl
- From: carl@montebello.ecom.unimelb.EDU.AU (Carl Brewer)
- Subject: Re: Unix Viruses. Are there any??
- Message-ID: <9302314.5488@mulga.cs.mu.OZ.AU>
- Sender: news@cs.mu.OZ.AU
- Organization: Dept. Engineering Computer Resources, Melbourne Uni.
- References: <senetza.727648754@honte> <1jootkINNhrv@matt.ksu.ksu.edu> <1jotp8INNiu@matt.ksu.ksu.edu>
- Date: Sat, 23 Jan 1993 03:50:00 GMT
- Lines: 36
-
- In article <1jotp8INNiu@matt.ksu.ksu.edu> probreak@matt.ksu.ksu.edu (James Michael Chacon) writes:
- >senetza@sigma.uleth.ca (Len Senetza) writes:
- >
- >>so, get the source for something like ls (it's on ftp.uu.net). then
- >>modify it so that it attaches a binary file which does x (x can be
- >>innocuous [print a smilie on the console] or destructive [halt]) to a
- >>system command (mkdir) which is installed suid. then, go talk to the
- >>sysadmin and tell them that there is something wrong with your
- >>directory. when they cd to it and do an 'ls' (your version), bango --
- >>virus. this 'x' thing that the binary file does can also include
- >>copying itself to other programs.
-
- 1: this is a trojan horse, not a virus.
-
- >
- >>so, if root executes your ls, then x is attached to some program in the
- >>system. have your x only do it to programs which are suid. then it's
- >>all over the place; memory protection and file access controls fail
- >>here.
- >
- >>this assumes that root has . in its path, and how many root accounts
- >>out there do?
- >
- >No, this assumes root has . at the FRONT of his/her path. This of course is
- >extremely stupid and I believe covered in the FAQ.
- >
- >A scenerio like this assumes that the sysadmin is a pretty trusting person
- >and probably already has large security holes in the system.
-
- a scenario like this assumes that the sysadmin should not be a sysadmin.
-
- --
- Annal Natrach, Usthvah Spethed, carl@ecr.mu.oz.au (IRC: Bleve)
- Dochoel Dienve carl@munagin.ee.mu.oz.au
- carl@montebello.ecom.unimelb.EDU.AU
- Merlin, where are you? Call your dragon, to weave a mist...
-