Re: [Full-Disclosure] Security hole in Confixx backup script

From: Dirk Pirschel (dirk_at_pirschel.de)
Date: 07/27/04

  • Next message: Paul Schmehl: "Re: FW: [Full-Disclosure] Question for DNS pros"
    To: full-disclosure@lists.netsys.com
    Date: Tue, 27 Jul 2004 01:57:04 +0200
    
    
    

    Hi,

    * Dirk Pirschel wrote on Fri, 25 Jun 2004 at 15:08 +0200:

    > A malicious backup request via the webinterface might be used by any
    > user to read files located in /root (which is the default installation
    > directory of confixx).

    Confixx does a "cd $dir; tar czf ..." without any error checking. If
    the target directory does not exist, the backup is done in the current
    working directory, which is /root.

    It is possible to retrieve *any* directory by replacing $HOME/files or
    $HOME/html with a symlink.

    > If you are using confixx, you should disable the backup script.

    -Dirk

    -- 
    Linux - Life is too short for reboots
    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Paul Schmehl: "Re: FW: [Full-Disclosure] Question for DNS pros"

    Relevant Pages

    • Re: Seniors Need Help! Help Retrieve Deleted Excel Document
      ... Backup, backup, backup, always backup your files ... at least act surprised if you actually do retrieve your file. ... Related Information -- File Recovery ... > Have you emptied the Recycle Bin? ...
      (microsoft.public.excel.newusers)
    • Re: Debian OS Backup
      ... Can I use an external hard drive to backup the operating system ... rdiff-backup is a script, written in pythonthat backs up one direc‐ ... The target directory ends up a copy of the ... or make your own using Debian Live. ...
      (Debian-User)
    • Re: Back up to "web" (online storage)
      ... you may be able to retrieve it in 3 hours based on download speed but how long to upload that same file... ... We would be in control of the remote server and would use a VPN ... > Have you thought how long a 35GB backup would take? ... > More importantly though lets say server stolen, fire or rebuild ...
      (microsoft.public.windows.server.sbs)
    • Re: Back up to "web" (online storage)
      ... you may be able to retrieve it in 3 hours based on download speed but how long to upload that same file... ... We would be in control of the remote server and would use a VPN ... > Have you thought how long a 35GB backup would take? ... > More importantly though lets say server stolen, fire or rebuild ...
      (microsoft.public.windows.server.sbs)
    • Re: xp backup restore
      ... "Pegasus (MVP)" wrote: ... In future remember that creating a backup process is ... The other half is to retrieve some ... external hard drive.I run the backup restore. ...
      (microsoft.public.windowsxp.general)