|
|
ru.linux- RU.LINUX --------------------------------------------------------------------- From : Sergey Lentsov 2:4615/71.10 05 Apr 2001 17:11:24 To : All Subject : URL: http://lwn.net/2001/0405/security.php3 --------------------------------------------------------------------------------
[1][LWN Logo]
[2]Click Here
[LWN.net]
Sections:
[3]Main page
Security
[4]Kernel
[5]Distributions
[6]On the Desktop
[7]Development
[8]Commerce
[9]Linux in the news
[10]Announcements
[11]Linux History
[12]Letters
[13]All in one big page
See also: [14]last week's Security page.
[15]New Security Reports
[16]BEA/Tomcat JSP
[17]BEA DTV
[18]Commercial
[19]Updates
[20]2.2.19
[21]OpenSSH 2.5.2p2
[22]VIM statusline
[23]Kerberos libkrb4
[24]Multiple FTPd DOS
[25]Resources
[26]FreeS/WAN 1.9
[27]Alamo
[28]Events
Security
News and Editorials
New Linux worm Adore. A new variant of the Ramen and Lion worms
emerged this week, with the first effects of the worm showing up in
the form of reports of larger and larger numbers of lpd scans showing
up on the Incidents list. Initially, it was called the "Red" worm, but
the final name chosen (by whatever method these names get chosen)
appeared to be "Adore".
Adore exploits existing vulnerabilities in [29]LPRng and lpr (BugTraq
ID [30]1712), [31]wu-ftpd (BugTraq ID [32]1387), [33]bind (BugTraq ID
[34]2302) and [35]NFS/rpc.statd (BugTraq ID [36]1480).
The oldest of these vulnerabilities dates back to June of 2000. Fixes
for all of them have been widely distributed and can be found through
the links above. If your systems are up-to-date, then this worm is not
a problem. If they are not up-to-date, the chances they will be found
and cracked are growing larger and larger.
Alfred Huger posted [37]this description of the worm on the Incidents
list, which includes some statistics from the ARIS Analyzer service,
illustrating the worm's progress across different IP networks and
various nations. It also serves as a reminder that those of us whose
systems are not vulnerable to the worm are still affected, as our
systems are pummeled with scans and the network is pummeled with
worm-related traffic.
The SANS Institute also posted [38]an advisory for Adore, which
includes tools for detection and removal of the worm.
Engarde Secure Linux.
A new entrant into the "Secured Linux Distributions" category this
week is [39]Engarde Secure Linux. The [40]announcement for Engarde
indicates that it includes the Linux Intrusion Detection (LIDS)
system, Tripwire, OpenWall, snort and more.
Linux Kernel: No Back Door. An April Fool's joke, which described a
non-existent back door in the Linux kernel, was published in the
latest release of "Linux-Magazin", a monthly German magazine. As a
result, SuSE got a flood of user-support questions about the
"problem". They issued [41]this statement as a result. "None of the
claims are correct, which makes a kernel update unnecessary for this
particular problem".
The timing of this joke happened to be particularly bad, since there
are perfectly valid reports of security problems in the 2.2.18 kernel.
None of them are remotely exploitable and none of them are
"back-doors".
Red Hat modifies directory structure on ftp sites. Red Hat's ftp
sites, including ftp.redhat.com and updates.redhat.com, now have
modified directory structures. The changes are fairly clear and
understandable. The old structure has been modified in order to allow
for support of the various language-specific versions of Red Hat.
(Thanks to Christof Damian).
However, if you've got bookmarks, or, more importantly, update
programs with encoded URLs, you'll need to change them to accomodate
the new structure.
The security implications of open source software (IBM
developerWorks). [42]This IBM developerWorks article looks at free
software and security. It includes discussions with Eric Raymond,
Michael Warfield, and Theo de Raadt. "Another perk of open source is
that the software actually evolves and gets more secure over time.
Subject to constant peer review, the number of new vulnerabilities
discovered in the software will decrease over time when compared to
similar closed source software. But as more crackers seek and find the
better-hidden flaws in opaque programs, closed source software gets
less secure as time passes."
Whodunnit? (Economist). The Economist looks at [43]computer forensics.
"The most ambitious public example of this is the Honeynet Project, a
network of honeypot computers that was set up a couple of years ago by
Lance Spitzer of Sun Microsystems. Last week, the Honeynet Project
reached the conclusion of its "Forensic Challenge", a sort of digital
version of the game "Cluedo" ("Clue", to Americans), which attempts to
discover that, for example, "Miss Hackwell" did it to the Linux with
the Ramen worm. The challenge showed that analysing traces of an
attack by malicious hackers is not as easy as it sounds. "
Minor format change. Please note the links provided in the left column
of this week's edition. They provide a quick way to jump to the
discussion of a new vulnerability, an update to an old vulnerability
or other sections of this page. We know the Security Summary gets long
sometimes (this week is unusually light), so please let us know if you
find the new links of help or not. If you like the links, they were
suggested by Stuart Moore. If you don't like them, they are all our
fault.
Security Reports
BEA Weblogic and Apache Group's Tomcat JSP vulnerability.
Both BEA Weblogic and Apache Group's Tomcat 4.0 have been reported
vulnerable to a [44]URL JSP request source-code disclosure
vulnerability. Essentially, a URL with specific characters appended to
it can be used to return the source code of the JSP file. Tomcat 4.0
beta 3 is reported to fix the problem. No fix from BEA Weblogic is
currently listed.
BEA Weblogic directory transversal vulnerability.
[45]BEA Systems Weblogic Server 6.0 has been reported to contain a
directory transversal vulnerability which can be allowed to view files
on the server that are outside the webserver's directory. BEA has
released a fix for the problem.
Commercial products.
The following commercial products were reported to contain
vulnerabilities:
* [46]NetScreen ScreenOS contains a vulnerability that can allow the
firewall policy to be bypassed. Fixes for this problem are
available from the vendor. NetScreen ScreenOS is used on a line of
internet security products from [47]NetScreen Technologies.
* Cisco issued an [48]updated version of their advisory mentioned
[49]last week addressing a vulnerability in Cisco VPN 3000 series
concentrators. The only change between the two advisories was the
title of the advisory.
Updates
ptrace/execve/procfs race condition in the Linux kernel 2.2.18.
Exploits were released [50]last week for a [51]ptrace/execve/procfs
race condition in the Linux kernel 2.2.18. As a result, an upgrade to
Linux 2.2.19 is recommended.
This week, Alan Cox put up the [52]Linux 2.2.19 release notes, finally
giving the specifics on all the security-related fixes in 2.2.19 (all
thirteen of them!) and giving credit to the [53]OpenWall project and
Chris Evans, for the majority of the third-party testing and auditing
work that turned up these bugs. Fixes for the same bugs have also been
ported forward into the 2.4.X kernel series.
This week's updates:
* [54]Caldera, 2.2.19 security fixes backported to 2.2.10 and
2.2.14, the kernels used in various Caldera products
Previous updates:
* [55]Immunix (March 29th)
OpenSSH 2.5.2p2 released.
[56]OpenSSH 2.5.2p2 was announced [57]last week. It contains a number
of fixes (including improvements in the defenses against the passive
analysis attacks discussed in the [58]March 22nd LWN security page)
and quite a few new features as well.
This week's updates:
* [59]Trustix
* [60]Red Hat, links updated as a result of a directory restructure
on the update site
* [61]Slackware changelog notice
Previous updates:
* [62]Linux-Mandrake (March 29th)
* [63]Conectiva (March 29th)
* [64]Immunix (March 29th)
* [65]Red Hat (RH 7 only) (March 29th)
VIM statusline Text-Embedded Command Execution Vulnerability.
A security problem was reported in VIM [66]last week where VIM codes
could be maliciously embedded in files and then executed in
vim-enhanced or vim-X11.
This week's updates:
* [67]Immunix
Previous updates:
* [68]Red Hat (March 29th)
* [69]Linux-Mandrake (March 29th)
Kerberos libkrb4 race condition.
A race condition in libkrb4 that can be exploited to overwrite the
contents of any file on the system was reported [70]last week by Red
Hat.
This week's updates:
* [71]Immunix
Previous updates:
* [72]Red Hat (March 29th)
Denial-of-service vulnerability in FTP server implementations.
Check the [73]March 22nd LWN Security Summary for the original report.
Affected FTP daemons include ProFTPd, NetBSD FTP, PureFTPd (to some
variants on this attack), BeroFTPD, and FreeBSD FTP.
This week's updates:
* [74]ProFTPD 1.2.2rc1
Previous updates:
* [75]ProFTPd (workaround only) (March 22nd)
Resources
FreeS/WAN 1.9 kernel support.
Last week, [76]FreeS/WAN 1.9 was released, primarily providing
compatibility with the new 2.4.x kernels (2.4.2 is specifically
mentioned), though additional bugfixes and features are also included.
Note that 1.9 was released just before Linux kernel 2.2.19 was and,
you guessed it, another [77]minor update is needed to work with that
kernel.
Check the [78]FreeS/WAN home page for more information on this
project, which brings IPSEC and IKE support to Linux.
Rackspace announces an 'antidote' to 'knark'.
Rackspace has issued [79]a press release about a program it has
released to deal with the root toolkit "Knark". For more information
on Knark, check [80]this analysis of Knark by Toby Miller.
The interesting point of Knark is its use of a kernel module to hide
evidence of the toolkit. Alamo is another kernel module, "shamelessly
ripped off" of Knark that simply tries to undo what Knark does,
exposing the rootkit. It is based on the 2.2.14 kernel, but should
work for most 2.2.X kernels.
WARNING! APRIL FOOL'S JOKE!. Well, if you're going to mention an April
Fool's joke on any day except April 1st (and even then!), you have to
be careful that people don't take it seriously. That warning given,
check out the announcement for a new BSD variant, [81]ThomasBSD.
"ThomasBSD is based on OpenBSD, thus it is OpenBSD PLUS MORE,
mathematically making it (NetBSD PLUS MORE) PLUS MORE.
The epoch of ThomasBSD will be moved back from January 1st, 1970 to
January 1st, 1960. Whenever a security problem is found and fixed in
OpenBSD, this little shift will enable me to also correct the issue in
ThomasBSD and then send mail to security-related mailing lists stating
that 'this was fixed in ThomasBSD about ten years ago'
".
Events
Internet Security Conference 2001. A [82]reminder went out this week
for the upcoming Internet Security Conference 2001, being held the
first week of June in Los Angeles, CA, USA. "TISC is an educational
forum for security professionals and practitioners".
Upcoming security events.
Date Event Location
April 6-8, 2001. [83]Rubi Con 2001 Detroit, MI, USA.
April 8-12, 2001. [84]RSA Conference 2001 San Francisco, CA, USA.
April 17-18, 2001. [85]E-Security Conference New York City, NY, USA.
April 20-22, 2001. [86]First annual iC0N security conference
Cleveland, Ohio, USA.
April 22-25, 2001. [87]Techno-Security 2001 Myrtle Beach, SC, USA.
April 24-26, 2001. [88]Infosecurity Europe 2001 London, Britain, UK.
May 13-16, 2001. [89]2001 IEEE Symposium on Security Oakland, CA, USA.
May 13-16, 2001. [90]CHES 2001 Paris, France.
May 29, 2001. [91]Security of Mobile Multiagent Systems (SEMAS-2001)
Montreal, Canada.
May 31-June 1, 2001. [92]The first European Electronic Signatures
Summit London, England, UK.
June 1-3, 2001. [93]Summercon 2001 Amsterdam, Netherlands.
June 4-8, 2001. [94]TISC 2001 Los Angeles, CA, USA.
June 5-6, 2001. [95]2nd Annual IEEE Systems, Man, and Cybernetics
Information Assurance Workshop United States Military Academy,
Westpoint, New York, USA.
For additional security-related events, included training courses
(which we don't list above) and events further in the future, check
out Security Focus' [96]calendar, one of the primary resources we use
for building the above list. To submit an event directly to us, please
send a plain-text message to [97]lwn@lwn.net.
Section Editor: [98]Liz Coolbaugh
April 5, 2001
[99]Click Here
Secured Distributions:
[100]Engarde Secure Linux
[101]Immunix
[102]Nexus
[103]SLinux [104]NSA Security Enhanced
[105]Trustix
Security List Archives
[106]Bugtraq Archive
[107]Firewall Wizards Archive
[108]ISN Archive
Distribution-specific links
[109]Caldera Advisories
[110]Conectiva Updates
[111]Debian Alerts
[112]Kondara Advisories
[113]Esware Alerts
[114]LinuxPPC Security Updates
[115]Mandrake Updates
[116]Red Hat Errata
[117]SuSE Announcements
[118]Yellow Dog Errata
BSD-specific links
[119]BSDi
[120]FreeBSD
[121]NetBSD
[122]OpenBSD
Security mailing lists [123]Caldera
[124]Cobalt
[125]Conectiva
[126]Debian
[127]Esware
[128]FreeBSD
[129]Kondara
[130]LASER5
[131]Linux From Scratch
[132]Linux-Mandrake
[133]NetBSD
[134]OpenBSD
[135]Red Hat
[136]Slackware
[137]Stampede
[138]SuSE
[139]Trustix
[140]turboLinux
[141]Yellow Dog
Security Software Archives
[142]munitions
[143]ZedZ.net (formerly replay.com)
Miscellaneous Resources
[144]CERT
[145]CIAC
[146]Comp Sec News Daily
[147]Crypto-GRAM
[148]LinuxLock.org
[149]Linux Security Audit Project
[150]LinuxSecurity.com
[151]OpenSSH
[152]OpenSEC
[153]Security Focus
[154]SecurityPortal
[155]Next: Kernel
[156]Eklektix, Inc. Linux powered! Copyright Л 2001 [157]Eklektix,
Inc., all rights reserved
Linux (R) is a registered trademark of Linus Torvalds
References
1. http://lwn.net/
2. http://ads.tucows.com/click.ng/pageid=001-012-132-000-000-002-000-000-012
3. http://lwn.net/2001/0405/
4. http://lwn.net/2001/0405/kernel.php3
5. http://lwn.net/2001/0405/dists.php3
6. http://lwn.net/2001/0405/desktop.php3
7. http://lwn.net/2001/0405/devel.php3
8. http://lwn.net/2001/0405/commerce.php3
9. http://lwn.net/2001/0405/press.php3
10. http://lwn.net/2001/0405/announce.php3
11. http://lwn.net/2001/0405/history.php3
12. http://lwn.net/2001/0405/letters.php3
13. http://lwn.net/2001/0405/bigpage.php3
14. http://lwn.net/2001/0321/security.php3
15. http://lwn.net/2001/0405/security.php3#reports
16. http://lwn.net/2001/0405/security.php3#beatomcat
17. http://lwn.net/2001/0405/security.php3#bea
18. http://lwn.net/2001/0405/security.php3#commercial
19. http://lwn.net/2001/0405/security.php3#updates
20. http://lwn.net/2001/0405/security.php3#kernelptrace
21. http://lwn.net/2001/0405/security.php3#openssh
22. http://lwn.net/2001/0405/security.php3#vim
23. http://lwn.net/2001/0405/security.php3#kerberos
24. http://lwn.net/2001/0405/security.php3#ftpds
25. http://lwn.net/2001/0405/security.php3#resources
26. http://lwn.net/2001/0405/security.php3#freeswan
27. http://lwn.net/2001/0405/security.php3#alamo
28. http://lwn.net/2001/0405/security.php3#events
29. http://lwn.net/2001/0301/security.php3#lpr/lprng
30. http://www.securityfocus.com/bid/1712
31. http://lwn.net/2001/0125/security.php3#wu-ftpd/tmprace
32. http://www.securityfocus.com/bid/1387
33. http://lwn.net/2001/0301/security.php3#bind
34. http://www.securityfocus.com/bid/2302
35. http://lwn.net/2000/0817/security.php3#nfs/rpc.statd
36. http://www.securityfocus.com/bid/1480
37. http://lwn.net/2001/0405/a/adore-ARIS.php3
38. http://lwn.net/2001/0405/a/sans-adore.php3
39. http://www.engardelinux.org/
40. http://www.engardelinux.org/announce.html
41. http://lwn.net/2001/0405/a/suse-nobackdoor.php3
42.
http://www-106.ibm.com/developerworks/linux/library/l-oss.html?open&l=252,t=gr,p
=SecImpOS
43. http://www.economist.com/displayStory.cfm?Story_ID=550004
44. http://www.securityfocus.com/bid/2527
45. http://www.securityfocus.com/bid/2513
46. http://www.securityfocus.com/bid/2523
47. http://www.netscreen.com/aboutus/index.html
48. http://lwn.net/2001/0405/a/cisco-vpn3000.php3
49. http://lwn.net/2001/0329/security.php3#commercial
50. http://lwn.net/2001/0329/security.php3#kernelptrace
51.
http://securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26ti
d%3D172196%26fromthread%3D0%26threads%3D1%26start%3D2001-03-25%26end%3D2001-03-3
1%26
52. http://www.linux.org.uk/VERSION/relnotes.2219.html
53. http://www.openwall.org/
54. http://lwn.net/2001/0405/a/caldera-backport.php3
55. http://lwn.net/2001/0329/a/im-kernel.php3
56. http://lwn.net/2001/0405/a/openssh-2.5.2p2.php3
57. http://lwn.net/2001/0329/security.php3#openssh
58. http://lwn.net/2001/0322/security.php3#sshpassive
59. http://lwn.net/2001/0405/a/tr-openssh.php3
60. http://lwn.net/2001/0405/a/rh-openssh2.php3
61. http://www.slackware.com/changelog/current.php?cpu=i386
62. http://lwn.net/2001/0329/a/lm-openssh.php3
63. http://lwn.net/2001/0329/a/con-openssh.php3
64. http://lwn.net/2001/0329/a/im-openssh.php3
65. http://lwn.net/2001/0329/a/rh-openssh.php3
66. http://lwn.net/2001/0329/security.php3#vim
67. http://lwn.net/2001/0405/a/im-vim.php3
68. http://lwn.net/2001/0329/a/rh-vim.php3
69. http://lwn.net/2001/0329/a/lm-vim.php3
70. http://lwn.net/2001/0329/security.php3#kerberos
71. http://lwn.net/2001/0405/a/im-kerberos.php3
72. http://lwn.net/2001/0329/a/rh-kerberos.php3
73. http://lwn.net/2001/0322/security.php3#ftpds
74. http://freshmeat.net/releases/44640/
75. http://lwn.net/2001/0322/a/proftpd-dos.php3
76. http://www.appwatch.com/Linux/App/1461/S/1/history.html
77. http://www.sandelman.ottawa.on.ca/linux-ipsec/html/2001/04/msg00042.html
78. http://www.freeswan.org/
79. http://lwn.net/2001/0405/a/alamo.php3
80.
http://www.securityfocus.com/templates/forum_message.html?forum=2&head=4871&id=4
871
81. http://lwn.net/2001/0405/a/thomasbsd.php3
82. http://lwn.net/2001/0405/a/isc2001.php3
83. http://www.rubi-con.org/
84. http://www.rsasecurity.com/conference/rsa2001/index2.html
85. http://www.esecurityexpo.com/mainmenu.asp
86. http://lwn.net/2001/0208/a/iC0N.php3
87. http://www.techsec.com/html/Conferences.html
88. http://www.infosec.co.uk/page.cfm
89. http://www.ieee-security.org/TC/sp2001.html
90. http://www.ece.wpi.edu/Research/crypt/ches/start.html
91. http://www.dfki.de/~kuf/semas/
92.
http://www.iqpc.com/cgi-bin/templates/98485262029583740234300003/genevent.html?e
vent=1525&topic=
93. http://www.summercon.org/announcements/
94. http://www.tisc2001.com/
95. http://www.itoc.usma.edu/Workshop/2001/Workshop2001.htm
96. http://securityfocus.com/calendar
97. mailto:lwn@lwn.net
98. mailto:lwn@lwn.net
99. http://ads.tucows.com/click.ng/buttonpos=lwnbuttonsecurity
100. http://www.engardelinux.org/
101. http://www.immunix.org/
102. http://Nexus-Project.net/
103. http://www.slinux.org/
104. http://www.nsa.gov/selinux/
105. http://www.trustix.com/
106. http://www.securityfocus.com/bugtraq/archive/
107. http://www.nfr.net/firewall-wizards/
108. http://www.jammed.com/Lists/ISN/
109. http://www.calderasystems.com/support/security/
110. http://www.conectiva.com.br/atualizacoes/
111. http://www.debian.org/security/
112. http://www.kondara.org/errata/k12-security.html
113. http://www.esware.com/actualizaciones.html
114. http://linuxppc.org/security/advisories/
115. http://www.linux-mandrake.com/en/fupdates.php3
116. http://www.redhat.com/support/errata/index.html
117. http://www.suse.de/security/index.html
118. http://www.yellowdoglinux.com/resources/errata.shtml
119. http://www.BSDI.COM/services/support/patches/
120. http://www.freebsd.org/security/security.html
121. http://www.NetBSD.ORG/Security/
122. http://www.openbsd.org/security.html
123. http://www.calderasystems.com/support/forums/announce.html
124. http://www.cobalt.com/support/resources/usergroups.html
125. http://distro.conectiva.com.br/atualizacoes/
126. http://www.debian.org/MailingLists/subscribe
127. http://www.esware.com/lista_correo.html
128. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
129. http://www.kondara.org/mailinglist.html.en
130. http://l5web.laser5.co.jp/ml/ml.html
131. http://www.linuxfromscratch.org/services/mailinglistinfo.php
132. http://www.linux-mandrake.com/en/flists.php3
133. http://www.netbsd.org/MailingLists/
134. http://www.openbsd.org/mail.html
135. http://www.redhat.com/mailing-lists/
136. http://www.slackware.com/lists/
137. http://www.stampede.org/mailinglists.php3
138. http://www.suse.com/en/support/mailinglists/index.html
139. http://www.trustix.net/support/
140. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
141. http://lists.yellowdoglinux.com/ydl_updates.shtml
142. http://munitions.vipul.net/
143. http://www.zedz.net/
144. http://www.cert.org/nav/alerts.html
145. http://ciac.llnl.gov/ciac/
146. http://www.MountainWave.com/
147. http://www.counterpane.com/crypto-gram.html
148. http://linuxlock.org/
149. http://lsap.org/
150. http://linuxsecurity.com/
151. http://www.openssh.com/
152. http://www.opensec.net/
153. http://www.securityfocus.com/
154. http://www.securityportal.com/
155. http://lwn.net/2001/0405/kernel.php3
156. http://www.eklektix.com/
157. http://www.eklektix.com/
--- ifmail v.2.14.os7-aks1
* Origin: Unknown (2:4615/71.10@fidonet)
Вернуться к списку тем, сортированных по: возрастание даты уменьшение даты тема автор
Архивное /ru.linux/203089efb943f.html, оценка из 5, голосов 10
|