home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!pipex!warwick!uknet!comlab.ox.ac.uk!pcl
- From: pcl@ox.ac.uk (Paul C Leyland)
- Newsgroups: comp.security.misc
- Subject: Re: Unix Viruses. Are there any??
- Message-ID: <PCL.93Jan25112838@rhodium.ox.ac.uk>
- Date: 25 Jan 93 11:28:38 GMT
- References: <1993Jan15.090426.12195@unix.brighton.ac.uk> <17988@umd5.umd.edu>
- <senetza.727648754@honte>
- Organization: Oxford University Computing Services, 13 Banbury Rd Oxford OX2
- 6NN
- Lines: 37
- In-reply-to: senetza@sigma.uleth.ca's message of 21 Jan 93 20:39:14 GMT
-
- In article <senetza.727648754@honte> senetza@sigma.uleth.ca (Len Senetza) writes:
-
- Description of perverted ls(1) deleted.
-
- so, if root executes your ls, then x is attached to some program in the
- system. have your x only do it to programs which are suid. then it's
- all over the place; memory protection and file access controls fail
- here.
-
- this assumes that root has . in its path, and how many root accounts
- out there do?
-
-
- Mine don't. Long time ago, in a previous life, the site I was
- sysadmin for got bitten by this very trojan (except someone
- implemented it as a shell-script rather than a binary). It was done
- for a "joke". At the time, I was 1200 miles away on vacation. When I
- got back, the joker had several interesting interviews with me, his
- supervisor and the head of the faculty.
-
- Several consequences:
- 1) Root never has . in its path
- 2) The joker stopped playing dangerous games, and went on to be
- a good system hacker.
- 3) Demonstrated that my insistence on good backups wasn't purely
- obsessional, but was actually vital to a research group.
- 4) The victim superuser, learned to type \/bin/su - root
- to avoid some of the more obvious su trojans.
-
-
- Paul
- --
- Paul Leyland <pcl@oxford.ac.uk> | Hanging on in quiet desperation is
- Oxford University Computing Service | the English way.
- 13 Banbury Road, Oxford, OX2 6NN, UK | The time is come, the song is over.
- Tel: +44-865-273200 Fax: +44-865-273275 | Thought I'd something more to say.
- Finger pcl@black.ox.ac.uk for PGP key |
-