Главная страница


ru.linux

 
 - RU.LINUX ---------------------------------------------------------------------
 From : Sergey Lentsov                       2:4615/71.10   05 Apr 2001  17:11:24
 To : All
 Subject : URL: http://lwn.net/2001/0405/security.php3
 -------------------------------------------------------------------------------- 
 
    [1][LWN Logo] 
    
                                [2]Click Here 
    [LWN.net]
    
    Sections:
     [3]Main page
     Security
     [4]Kernel
     [5]Distributions
     [6]On the Desktop
     [7]Development
     [8]Commerce
     [9]Linux in the news
     [10]Announcements
     [11]Linux History
     [12]Letters
    [13]All in one big page
    
    See also: [14]last week's Security page.
    [15]New Security Reports
    [16]BEA/Tomcat JSP
    [17]BEA DTV
    [18]Commercial
    [19]Updates
    [20]2.2.19
    [21]OpenSSH 2.5.2p2
    [22]VIM statusline
    [23]Kerberos libkrb4
    [24]Multiple FTPd DOS
    [25]Resources
    [26]FreeS/WAN 1.9
    [27]Alamo
    [28]Events
    
 Security
 
 News and Editorials
 
    New Linux worm Adore. A new variant of the Ramen and Lion worms
    emerged this week, with the first effects of the worm showing up in
    the form of reports of larger and larger numbers of lpd scans showing
    up on the Incidents list. Initially, it was called the "Red" worm, but
    the final name chosen (by whatever method these names get chosen)
    appeared to be "Adore".
    
    Adore exploits existing vulnerabilities in [29]LPRng and lpr (BugTraq
    ID [30]1712), [31]wu-ftpd (BugTraq ID [32]1387), [33]bind (BugTraq ID
    [34]2302) and [35]NFS/rpc.statd (BugTraq ID [36]1480).
    
    The oldest of these vulnerabilities dates back to June of 2000. Fixes
    for all of them have been widely distributed and can be found through
    the links above. If your systems are up-to-date, then this worm is not
    a problem. If they are not up-to-date, the chances they will be found
    and cracked are growing larger and larger.
    
    Alfred Huger posted [37]this description of the worm on the Incidents
    list, which includes some statistics from the ARIS Analyzer service,
    illustrating the worm's progress across different IP networks and
    various nations. It also serves as a reminder that those of us whose
    systems are not vulnerable to the worm are still affected, as our
    systems are pummeled with scans and the network is pummeled with
    worm-related traffic.
    
    The SANS Institute also posted [38]an advisory for Adore, which
    includes tools for detection and removal of the worm.
    
    Engarde Secure Linux.
    A new entrant into the "Secured Linux Distributions" category this
    week is [39]Engarde Secure Linux. The [40]announcement for Engarde
    indicates that it includes the Linux Intrusion Detection (LIDS)
    system, Tripwire, OpenWall, snort and more.
    
    Linux Kernel: No Back Door. An April Fool's joke, which described a
    non-existent back door in the Linux kernel, was published in the
    latest release of "Linux-Magazin", a monthly German magazine. As a
    result, SuSE got a flood of user-support questions about the
    "problem". They issued [41]this statement as a result. "None of the
    claims are correct, which makes a kernel update unnecessary for this
    particular problem".
    
    The timing of this joke happened to be particularly bad, since there
    are perfectly valid reports of security problems in the 2.2.18 kernel.
    None of them are remotely exploitable and none of them are
    "back-doors".
    
    Red Hat modifies directory structure on ftp sites. Red Hat's ftp
    sites, including ftp.redhat.com and updates.redhat.com, now have
    modified directory structures. The changes are fairly clear and
    understandable. The old structure has been modified in order to allow
    for support of the various language-specific versions of Red Hat.
    (Thanks to Christof Damian).
    
    However, if you've got bookmarks, or, more importantly, update
    programs with encoded URLs, you'll need to change them to accomodate
    the new structure.
    
    The security implications of open source software (IBM
    developerWorks). [42]This IBM developerWorks article looks at free
    software and security. It includes discussions with Eric Raymond,
    Michael Warfield, and Theo de Raadt. "Another perk of open source is
    that the software actually evolves and gets more secure over time.
    Subject to constant peer review, the number of new vulnerabilities
    discovered in the software will decrease over time when compared to
    similar closed source software. But as more crackers seek and find the
    better-hidden flaws in opaque programs, closed source software gets
    less secure as time passes."
    
    Whodunnit? (Economist). The Economist looks at [43]computer forensics.
    "The most ambitious public example of this is the Honeynet Project, a
    network of honeypot computers that was set up a couple of years ago by
    Lance Spitzer of Sun Microsystems. Last week, the Honeynet Project
    reached the conclusion of its "Forensic Challenge", a sort of digital
    version of the game "Cluedo" ("Clue", to Americans), which attempts to
    discover that, for example, "Miss Hackwell" did it to the Linux with
    the Ramen worm. The challenge showed that analysing traces of an
    attack by malicious hackers is not as easy as it sounds. "
    
    Minor format change. Please note the links provided in the left column
    of this week's edition. They provide a quick way to jump to the
    discussion of a new vulnerability, an update to an old vulnerability
    or other sections of this page. We know the Security Summary gets long
    sometimes (this week is unusually light), so please let us know if you
    find the new links of help or not. If you like the links, they were
    suggested by Stuart Moore. If you don't like them, they are all our
    fault.
    
 Security Reports
 
    BEA Weblogic and Apache Group's Tomcat JSP vulnerability.
    Both BEA Weblogic and Apache Group's Tomcat 4.0 have been reported
    vulnerable to a [44]URL JSP request source-code disclosure
    vulnerability. Essentially, a URL with specific characters appended to
    it can be used to return the source code of the JSP file. Tomcat 4.0
    beta 3 is reported to fix the problem. No fix from BEA Weblogic is
    currently listed.
    
    BEA Weblogic directory transversal vulnerability.
    [45]BEA Systems Weblogic Server 6.0 has been reported to contain a
    directory transversal vulnerability which can be allowed to view files
    on the server that are outside the webserver's directory. BEA has
    released a fix for the problem.
    
    Commercial products.
    The following commercial products were reported to contain
    vulnerabilities:
      * [46]NetScreen ScreenOS contains a vulnerability that can allow the
        firewall policy to be bypassed. Fixes for this problem are
        available from the vendor. NetScreen ScreenOS is used on a line of
        internet security products from [47]NetScreen Technologies.
      * Cisco issued an [48]updated version of their advisory mentioned
        [49]last week addressing a vulnerability in Cisco VPN 3000 series
        concentrators. The only change between the two advisories was the
        title of the advisory.
        
 Updates
 
    ptrace/execve/procfs race condition in the Linux kernel 2.2.18.
    Exploits were released [50]last week for a [51]ptrace/execve/procfs
    race condition in the Linux kernel 2.2.18. As a result, an upgrade to
    Linux 2.2.19 is recommended.
    
    This week, Alan Cox put up the [52]Linux 2.2.19 release notes, finally
    giving the specifics on all the security-related fixes in 2.2.19 (all
    thirteen of them!) and giving credit to the [53]OpenWall project and
    Chris Evans, for the majority of the third-party testing and auditing
    work that turned up these bugs. Fixes for the same bugs have also been
    ported forward into the 2.4.X kernel series.
    
    This week's updates:
      * [54]Caldera, 2.2.19 security fixes backported to 2.2.10 and
        2.2.14, the kernels used in various Caldera products
        
    Previous updates:
      * [55]Immunix (March 29th)
        
    OpenSSH 2.5.2p2 released.
    [56]OpenSSH 2.5.2p2 was announced [57]last week. It contains a number
    of fixes (including improvements in the defenses against the passive
    analysis attacks discussed in the [58]March 22nd LWN security page)
    and quite a few new features as well.
    
    This week's updates:
      * [59]Trustix
      * [60]Red Hat, links updated as a result of a directory restructure
        on the update site
      * [61]Slackware changelog notice
        
    Previous updates:
      * [62]Linux-Mandrake (March 29th)
      * [63]Conectiva (March 29th)
      * [64]Immunix (March 29th)
      * [65]Red Hat (RH 7 only) (March 29th)
        
    VIM statusline Text-Embedded Command Execution Vulnerability.
    A security problem was reported in VIM [66]last week where VIM codes
    could be maliciously embedded in files and then executed in
    vim-enhanced or vim-X11.
    
    This week's updates:
      * [67]Immunix
        
    Previous updates:
      * [68]Red Hat (March 29th)
      * [69]Linux-Mandrake (March 29th)
        
    Kerberos libkrb4 race condition.
    A race condition in libkrb4 that can be exploited to overwrite the
    contents of any file on the system was reported [70]last week by Red
    Hat.
    
    This week's updates:
      * [71]Immunix
        
    Previous updates:
      * [72]Red Hat (March 29th)
        
    Denial-of-service vulnerability in FTP server implementations.
    Check the [73]March 22nd LWN Security Summary for the original report.
    Affected FTP daemons include ProFTPd, NetBSD FTP, PureFTPd (to some
    variants on this attack), BeroFTPD, and FreeBSD FTP.
    
    This week's updates:
      * [74]ProFTPD 1.2.2rc1
        
    Previous updates:
      * [75]ProFTPd (workaround only) (March 22nd)
        
 Resources
 
    FreeS/WAN 1.9 kernel support.
    Last week, [76]FreeS/WAN 1.9 was released, primarily providing
    compatibility with the new 2.4.x kernels (2.4.2 is specifically
    mentioned), though additional bugfixes and features are also included.
    Note that 1.9 was released just before Linux kernel 2.2.19 was and,
    you guessed it, another [77]minor update is needed to work with that
    kernel.
    
    Check the [78]FreeS/WAN home page for more information on this
    project, which brings IPSEC and IKE support to Linux.
    
    Rackspace announces an 'antidote' to 'knark'.
    Rackspace has issued [79]a press release about a program it has
    released to deal with the root toolkit "Knark". For more information
    on Knark, check [80]this analysis of Knark by Toby Miller.
    
    The interesting point of Knark is its use of a kernel module to hide
    evidence of the toolkit. Alamo is another kernel module, "shamelessly
    ripped off" of Knark that simply tries to undo what Knark does,
    exposing the rootkit. It is based on the 2.2.14 kernel, but should
    work for most 2.2.X kernels.
    
    WARNING! APRIL FOOL'S JOKE!. Well, if you're going to mention an April
    Fool's joke on any day except April 1st (and even then!), you have to
    be careful that people don't take it seriously. That warning given,
    check out the announcement for a new BSD variant, [81]ThomasBSD.
    "ThomasBSD is based on OpenBSD, thus it is OpenBSD PLUS MORE,
    mathematically making it (NetBSD PLUS MORE) PLUS MORE. 
    
    The epoch of ThomasBSD will be moved back from January 1st, 1970 to
    January 1st, 1960. Whenever a security problem is found and fixed in
    OpenBSD, this little shift will enable me to also correct the issue in
    ThomasBSD and then send mail to security-related mailing lists stating
    that 'this was fixed in ThomasBSD about ten years ago'
    ".
    
 Events
 
    Internet Security Conference 2001. A [82]reminder went out this week
    for the upcoming Internet Security Conference 2001, being held the
    first week of June in Los Angeles, CA, USA. "TISC is an educational
    forum for security professionals and practitioners".
    
    Upcoming security events.
    
    Date Event Location
    April 6-8, 2001. [83]Rubi Con 2001 Detroit, MI, USA.
    April 8-12, 2001. [84]RSA Conference 2001 San Francisco, CA, USA.
    April 17-18, 2001. [85]E-Security Conference New York City, NY, USA.
    April 20-22, 2001. [86]First annual iC0N security conference
    Cleveland, Ohio, USA.
    April 22-25, 2001. [87]Techno-Security 2001 Myrtle Beach, SC, USA.
    April 24-26, 2001. [88]Infosecurity Europe 2001 London, Britain, UK.
    May 13-16, 2001. [89]2001 IEEE Symposium on Security Oakland, CA, USA.
    May 13-16, 2001. [90]CHES 2001 Paris, France.
    May 29, 2001. [91]Security of Mobile Multiagent Systems (SEMAS-2001)
    Montreal, Canada.
    May 31-June 1, 2001. [92]The first European Electronic Signatures
    Summit London, England, UK.
    June 1-3, 2001. [93]Summercon 2001 Amsterdam, Netherlands.
    June 4-8, 2001. [94]TISC 2001 Los Angeles, CA, USA.
    June 5-6, 2001. [95]2nd Annual IEEE Systems, Man, and Cybernetics
    Information Assurance Workshop United States Military Academy,
    Westpoint, New York, USA.
    
    For additional security-related events, included training courses
    (which we don't list above) and events further in the future, check
    out Security Focus' [96]calendar, one of the primary resources we use
    for building the above list. To submit an event directly to us, please
    send a plain-text message to [97]lwn@lwn.net.
    
    Section Editor: [98]Liz Coolbaugh
    April 5, 2001
    
                               [99]Click Here 
    Secured Distributions:
    [100]Engarde Secure Linux
    [101]Immunix
    [102]Nexus
    [103]SLinux [104]NSA Security Enhanced
    [105]Trustix
    Security List Archives
    [106]Bugtraq Archive
    [107]Firewall Wizards Archive
    [108]ISN Archive
    Distribution-specific links
    [109]Caldera Advisories
    [110]Conectiva Updates
    [111]Debian Alerts
    [112]Kondara Advisories
    [113]Esware Alerts
    [114]LinuxPPC Security Updates
    [115]Mandrake Updates
    [116]Red Hat Errata
    [117]SuSE Announcements
    [118]Yellow Dog Errata
    BSD-specific links
    [119]BSDi
    [120]FreeBSD
    [121]NetBSD
    [122]OpenBSD
    Security mailing lists [123]Caldera
    [124]Cobalt
    [125]Conectiva
    [126]Debian
    [127]Esware
    [128]FreeBSD
    [129]Kondara
    [130]LASER5
    [131]Linux From Scratch
    [132]Linux-Mandrake
    [133]NetBSD
    [134]OpenBSD
    [135]Red Hat
    [136]Slackware
    [137]Stampede
    [138]SuSE
    [139]Trustix
    [140]turboLinux
    [141]Yellow Dog
    Security Software Archives
    [142]munitions
    [143]ZedZ.net (formerly replay.com)
    Miscellaneous Resources
    [144]CERT
    [145]CIAC
    [146]Comp Sec News Daily
    [147]Crypto-GRAM
    [148]LinuxLock.org
    [149]Linux Security Audit Project
    [150]LinuxSecurity.com
    [151]OpenSSH
    [152]OpenSEC
    [153]Security Focus
    [154]SecurityPortal
    
    
                                                         [155]Next: Kernel
    
    [156]Eklektix, Inc. Linux powered! Copyright Л 2001 [157]Eklektix,
    Inc., all rights reserved
    Linux (R) is a registered trademark of Linus Torvalds
 
 References
 
    1. http://lwn.net/
    2. http://ads.tucows.com/click.ng/pageid=001-012-132-000-000-002-000-000-012
    3. http://lwn.net/2001/0405/
    4. http://lwn.net/2001/0405/kernel.php3
    5. http://lwn.net/2001/0405/dists.php3
    6. http://lwn.net/2001/0405/desktop.php3
    7. http://lwn.net/2001/0405/devel.php3
    8. http://lwn.net/2001/0405/commerce.php3
    9. http://lwn.net/2001/0405/press.php3
   10. http://lwn.net/2001/0405/announce.php3
   11. http://lwn.net/2001/0405/history.php3
   12. http://lwn.net/2001/0405/letters.php3
   13. http://lwn.net/2001/0405/bigpage.php3
   14. http://lwn.net/2001/0321/security.php3
   15. http://lwn.net/2001/0405/security.php3#reports
   16. http://lwn.net/2001/0405/security.php3#beatomcat
   17. http://lwn.net/2001/0405/security.php3#bea
   18. http://lwn.net/2001/0405/security.php3#commercial
   19. http://lwn.net/2001/0405/security.php3#updates
   20. http://lwn.net/2001/0405/security.php3#kernelptrace
   21. http://lwn.net/2001/0405/security.php3#openssh
   22. http://lwn.net/2001/0405/security.php3#vim
   23. http://lwn.net/2001/0405/security.php3#kerberos
   24. http://lwn.net/2001/0405/security.php3#ftpds
   25. http://lwn.net/2001/0405/security.php3#resources
   26. http://lwn.net/2001/0405/security.php3#freeswan
   27. http://lwn.net/2001/0405/security.php3#alamo
   28. http://lwn.net/2001/0405/security.php3#events
   29. http://lwn.net/2001/0301/security.php3#lpr/lprng
   30. http://www.securityfocus.com/bid/1712
   31. http://lwn.net/2001/0125/security.php3#wu-ftpd/tmprace
   32. http://www.securityfocus.com/bid/1387
   33. http://lwn.net/2001/0301/security.php3#bind
   34. http://www.securityfocus.com/bid/2302
   35. http://lwn.net/2000/0817/security.php3#nfs/rpc.statd
   36. http://www.securityfocus.com/bid/1480
   37. http://lwn.net/2001/0405/a/adore-ARIS.php3
   38. http://lwn.net/2001/0405/a/sans-adore.php3
   39. http://www.engardelinux.org/
   40. http://www.engardelinux.org/announce.html
   41. http://lwn.net/2001/0405/a/suse-nobackdoor.php3
   42.
 http://www-106.ibm.com/developerworks/linux/library/l-oss.html?open&l=252,t=gr,p
 =SecImpOS
   43. http://www.economist.com/displayStory.cfm?Story_ID=550004
   44. http://www.securityfocus.com/bid/2527
   45. http://www.securityfocus.com/bid/2513
   46. http://www.securityfocus.com/bid/2523
   47. http://www.netscreen.com/aboutus/index.html
   48. http://lwn.net/2001/0405/a/cisco-vpn3000.php3
   49. http://lwn.net/2001/0329/security.php3#commercial
   50. http://lwn.net/2001/0329/security.php3#kernelptrace
   51.
 http://securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26ti
 d%3D172196%26fromthread%3D0%26threads%3D1%26start%3D2001-03-25%26end%3D2001-03-3
 1%26
   52. http://www.linux.org.uk/VERSION/relnotes.2219.html
   53. http://www.openwall.org/
   54. http://lwn.net/2001/0405/a/caldera-backport.php3
   55. http://lwn.net/2001/0329/a/im-kernel.php3
   56. http://lwn.net/2001/0405/a/openssh-2.5.2p2.php3
   57. http://lwn.net/2001/0329/security.php3#openssh
   58. http://lwn.net/2001/0322/security.php3#sshpassive
   59. http://lwn.net/2001/0405/a/tr-openssh.php3
   60. http://lwn.net/2001/0405/a/rh-openssh2.php3
   61. http://www.slackware.com/changelog/current.php?cpu=i386
   62. http://lwn.net/2001/0329/a/lm-openssh.php3
   63. http://lwn.net/2001/0329/a/con-openssh.php3
   64. http://lwn.net/2001/0329/a/im-openssh.php3
   65. http://lwn.net/2001/0329/a/rh-openssh.php3
   66. http://lwn.net/2001/0329/security.php3#vim
   67. http://lwn.net/2001/0405/a/im-vim.php3
   68. http://lwn.net/2001/0329/a/rh-vim.php3
   69. http://lwn.net/2001/0329/a/lm-vim.php3
   70. http://lwn.net/2001/0329/security.php3#kerberos
   71. http://lwn.net/2001/0405/a/im-kerberos.php3
   72. http://lwn.net/2001/0329/a/rh-kerberos.php3
   73. http://lwn.net/2001/0322/security.php3#ftpds
   74. http://freshmeat.net/releases/44640/
   75. http://lwn.net/2001/0322/a/proftpd-dos.php3
   76. http://www.appwatch.com/Linux/App/1461/S/1/history.html
   77. http://www.sandelman.ottawa.on.ca/linux-ipsec/html/2001/04/msg00042.html
   78. http://www.freeswan.org/
   79. http://lwn.net/2001/0405/a/alamo.php3
   80.
 http://www.securityfocus.com/templates/forum_message.html?forum=2&head=4871&id=4
 871
   81. http://lwn.net/2001/0405/a/thomasbsd.php3
   82. http://lwn.net/2001/0405/a/isc2001.php3
   83. http://www.rubi-con.org/
   84. http://www.rsasecurity.com/conference/rsa2001/index2.html
   85. http://www.esecurityexpo.com/mainmenu.asp
   86. http://lwn.net/2001/0208/a/iC0N.php3
   87. http://www.techsec.com/html/Conferences.html
   88. http://www.infosec.co.uk/page.cfm
   89. http://www.ieee-security.org/TC/sp2001.html
   90. http://www.ece.wpi.edu/Research/crypt/ches/start.html
   91. http://www.dfki.de/~kuf/semas/
   92.
 http://www.iqpc.com/cgi-bin/templates/98485262029583740234300003/genevent.html?e
 vent=1525&topic=
   93. http://www.summercon.org/announcements/
   94. http://www.tisc2001.com/
   95. http://www.itoc.usma.edu/Workshop/2001/Workshop2001.htm
   96. http://securityfocus.com/calendar
   97. mailto:lwn@lwn.net
   98. mailto:lwn@lwn.net
   99. http://ads.tucows.com/click.ng/buttonpos=lwnbuttonsecurity
  100. http://www.engardelinux.org/
  101. http://www.immunix.org/
  102. http://Nexus-Project.net/
  103. http://www.slinux.org/
  104. http://www.nsa.gov/selinux/
  105. http://www.trustix.com/
  106. http://www.securityfocus.com/bugtraq/archive/
  107. http://www.nfr.net/firewall-wizards/
  108. http://www.jammed.com/Lists/ISN/
  109. http://www.calderasystems.com/support/security/
  110. http://www.conectiva.com.br/atualizacoes/
  111. http://www.debian.org/security/
  112. http://www.kondara.org/errata/k12-security.html
  113. http://www.esware.com/actualizaciones.html
  114. http://linuxppc.org/security/advisories/
  115. http://www.linux-mandrake.com/en/fupdates.php3
  116. http://www.redhat.com/support/errata/index.html
  117. http://www.suse.de/security/index.html
  118. http://www.yellowdoglinux.com/resources/errata.shtml
  119. http://www.BSDI.COM/services/support/patches/
  120. http://www.freebsd.org/security/security.html
  121. http://www.NetBSD.ORG/Security/
  122. http://www.openbsd.org/security.html
  123. http://www.calderasystems.com/support/forums/announce.html
  124. http://www.cobalt.com/support/resources/usergroups.html
  125. http://distro.conectiva.com.br/atualizacoes/
  126. http://www.debian.org/MailingLists/subscribe
  127. http://www.esware.com/lista_correo.html
  128. http://www.freebsd.org/handbook/eresources.html#ERESOURCES-MAIL
  129. http://www.kondara.org/mailinglist.html.en
  130. http://l5web.laser5.co.jp/ml/ml.html
  131. http://www.linuxfromscratch.org/services/mailinglistinfo.php
  132. http://www.linux-mandrake.com/en/flists.php3
  133. http://www.netbsd.org/MailingLists/
  134. http://www.openbsd.org/mail.html
  135. http://www.redhat.com/mailing-lists/
  136. http://www.slackware.com/lists/
  137. http://www.stampede.org/mailinglists.php3
  138. http://www.suse.com/en/support/mailinglists/index.html
  139. http://www.trustix.net/support/
  140. http://www.turbolinux.com/mailman/listinfo/tl-security-announce
  141. http://lists.yellowdoglinux.com/ydl_updates.shtml
  142. http://munitions.vipul.net/
  143. http://www.zedz.net/
  144. http://www.cert.org/nav/alerts.html
  145. http://ciac.llnl.gov/ciac/
  146. http://www.MountainWave.com/
  147. http://www.counterpane.com/crypto-gram.html
  148. http://linuxlock.org/
  149. http://lsap.org/
  150. http://linuxsecurity.com/
  151. http://www.openssh.com/
  152. http://www.opensec.net/
  153. http://www.securityfocus.com/
  154. http://www.securityportal.com/
  155. http://lwn.net/2001/0405/kernel.php3
  156. http://www.eklektix.com/
  157. http://www.eklektix.com/
 
 --- ifmail v.2.14.os7-aks1
  * Origin: Unknown (2:4615/71.10@fidonet)
 
 

Вернуться к списку тем, сортированных по: возрастание даты  уменьшение даты  тема  автор 

 Тема:    Автор:    Дата:  
 URL: http://lwn.net/2001/0405/security.php3   Sergey Lentsov   05 Apr 2001 17:11:24 
Архивное /ru.linux/203089efb943f.html, оценка 2 из 5, голосов 10
Яндекс.Метрика
Valid HTML 4.01 Transitional