Re: hard links on Linux create local DoS vulnerability and security problems

From: Bruno Lustosa (bruno_at_lustosa.net)
Date: 11/24/03

  • Next message: Steven Leikeim: "Re: hard links on Linux create local DoS vulnerability and security problems"
    Date: Mon, 24 Nov 2003 16:25:37 -0200
    To: bugtraq@securityfocus.com
    
    
    

    * Jakob Lell <jlell@JakobLell.de> [24-11-2003 16:11]:
    > Furthermore, users can even create links to a setuid binary. If there is a
    > security whole like a buffer overflow in any setuid binary, a cracker can
    > create a hard link to this file in his home directory. This link still exists
    > when the administrator has fixed the security whole by removing or replacing
    > the insecure program. This makes it possible for a cracker to keep a security
    > whole open until an exploit is available. It is even possible to create links
    > to every setuid program on the system. This doesn't create new security
    > wholes but makes it more likely that they are exploited.

    Just checked this on 2.6.0-test9, and it will not work.
    When you create a hard link to a setuid or any other file, it will
    inherit the same owner and mode of the original. However, if the
    original file is changed (owner, group, mode, or content), the link will
    reflect those changes as well.

    -- 
    Bruno Lustosa, aka Lofofora          | Email: bruno@lustosa.net
    Network Administrator/Web Programmer | ICQ UIN: 1406477
    Rio de Janeiro - Brazil              |
    
    



  • Next message: Steven Leikeim: "Re: hard links on Linux create local DoS vulnerability and security problems"

    Relevant Pages

    • [Full-Disclosure] Re: hard links on Linux create local DoS vulnerability and security problems
      ... This hard link continues to exist even if the original file ... > owner, it is still counted to his quota. ... > when the administrator has fixed the security whole by removing or replacing ...
      (Full-Disclosure)
    • [NEWS] eNom Domain Registration Services Domain Hijacking Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... eNom provides Internet domain name services. ... the owner of the domain ... Domain Transfer Request for EXAMPLE.XXX ...
      (Securiteam)
    • Re: Pentester convicted..
      ... > the owner didn't want me to have it but I brought it back to ... Concerned about Web Application Security? ... You have an option to go with a managed service or an enterprise software. ...
      (Pen-Test)
    • Re: GetNamedSecurityInfo - Read Owner pt II
      ... The Security Descriptor pointer ... > is much simplier than the raw PInvoke Win32 APIs. ... I am a system administrator, ... >> unsuccessful reading the owner of a file using Win APIs such as ...
      (microsoft.public.dotnet.languages.vb)
    • Re: GetNamedSecurityInfo - Read Owner pt II
      ... The Security Descriptor pointer ... > is much simplier than the raw PInvoke Win32 APIs. ... I am a system administrator, ... >> unsuccessful reading the owner of a file using Win APIs such as ...
      (microsoft.public.dotnet.framework.interop)