Looking for old Interbase proof-of-concept exploit

From: Charles 'core' Stevenson (core@bokeoa.com)
Date: 01/29/02


Date: Tue, 29 Jan 2002 05:39:54 -0700
From: Charles 'core' Stevenson <core@bokeoa.com>
To: "vuln-dev@securityfocus.com" <vuln-dev@securityfocus.com>

Hi,

I was reading up on the old Interbase hardcoded backdoor and I'm not
sure how to go about writing some code to interface with the server and
perform authentication and execute arbitrary commands. I wondered if
anyone has created a proof-of-concept exploit or if not has any
information on the protocol that could help me create my own.

Here's the hardcoded backdoor account information:

#define LOCKSMITH_USER "politically"
#define LOCKSMITH_PASSWORD "correct"

The server runs on port 3050. It is sometimes spawned from inetd:

#gds_db stream tcp nowait.30000 root
/usr/local/sbin/gds_inet_server gds_inet_server # InterBase Database
Remote Server

From reading the documentation I gather that it no longer needs to be
run through inetd. I was able to spawn the server by locally running it
with the '-d' flag.

References:

http://www.cert.org/advisories/CA-2001-01.html
http://list.cobalt.com/pipermail/cobalt-users/2001-January/030260.html
http://www.securityfocus.com/bid/2192

Any information would be great.

Best Regards,
Charles Stevenson



Relevant Pages

  • CEICW Fails at RegisterMSBOExchangeBP
    ... Ethernet adapter Server Local Area Connection: ... Call to Reading hardware selection returned ok. ... calling CNetCommit::ValidateRouterConnectionProperties. ... Call to Reading preferred DNS server IP returned ok. ...
    (microsoft.public.windows.server.sbs)
  • ICW Problem Error 0x80072581 Deleting the DNS record external NIC
    ... I am having major problems with the internet and email connection wizard in sbs 2004, curiously I have internet access however the wizard fails to complete during the network section when I try and add OWA and RWW web services. ... Server connects to the internet and provides access for server no clients attached as yet. ... Call to Reading hardware selection returned ok. ... Firewall Rule: SBS DHCP Client ...
    (microsoft.public.windows.server.sbs)
  • Re: Please Help CEICW Fails At Firewall For RWW
    ... I can log on as a user on to the server and then get the session to work. ... Call to Reading hardware selection returned ok. ... calling CNetCommit::ValidateRouterConnectionProperties. ... Call to Reading web publishing selection returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange server not running - Urgent
    ... I just rebooted the server and our email came streaming in. ... Call to Reading hardware selection returned ok. ... calling CNetCommit::ValidateRouterConnectionProperties. ... Call to Reading web publishing selection returned ok. ...
    (microsoft.public.windows.server.sbs)
  • RE: ceicw fails every time
    ... You have to rerun the CEICW to make sure your SBS 2003 server have right ... Calling CCertCommit::ValidatePropertyBag ... Call to Reading OWA publishing selection returned ok. ...
    (microsoft.public.windows.server.sbs)