home *** CD-ROM | disk | FTP | other *** search
- From: rob@wzv.win.tue.nl (Rob J. Nauta)
- Newsgroups: alt.security,comp.sys.novell,comp.security.misc
- Subject: Re: Netware Security Inquiry
- Message-ID: <3923@wzv.win.tue.nl>
- Date: 28 Sep 92 10:50:00 GMT
- References: <23448@hacgate.SCG.HAC.COM>
-
- Why bother with netware security ?
-
- The Dutch magazine 'computable' (a trade mag, not a real computer mag) of
- sept. 26 1992 has an article 'NGN-member discovers serious bug in Novell's
- Netware'. (NGN is the Dutch Novell User Group). Here's an excerpt:
-
- During the Lanvision days that the NGN organized last week, a serious
- bug in the network operating system Netware was discovered. It allows
- any user to take over the authorization level of every other
- Netware-user. The leak is supposed to be in every Netware release.
- NGN-president E. Fuld claims: During our traditional Nightware-party
- during the night of the first Lanvision day a researcher at one
- of the Dutch Universities demonstrated a program that uses the leak
- in Netware. Fuld refused to say who wrote the program, to protect the
- programmer and the university. He also refused to disclose the techical
- background of the leak. It is supposedly a trick where a user sends
- a command to teh fileserver and then pretends to be another logged-in
- user. As soon as a connection to the server is made, he gets the
- rights of the other user.
- If a programmer knows where to look, a program to exploit it is trivial,
- says Fuld to motivate his refusal to disclose any information.
- The NGN has made a copy of the program and has given it to a sales
- rep of Novell that flew it back to Novell's headquarters in Provo,Utah
- immediately. According to Fuld, an emergency meeting was called, where
- Drew Major, the developer of the Netware kernel was also present.
- B. Mellink of the NGN is currently developing a program that can
- detect if any user is abusing the bug.
- According to Fuld, all Netbios-based network operating systems have
- the same bug. This includes Lanserver and Lan Manager, since none of
- the operating systems uses encryption of network addresses.
- This way any user can send packets with a phony originating address.
- MicroSoft, the company that produces LanManager, refused comment.
- Though the program is not known to be in wrong hands, the NGN
- advises not to store any important information on Novell-networks.
- Network Administrators are also advised not to log in while other
- users are logged in. Novell has taken over the warning.
-
- One thing is curious, why would someone assume that discovering
- a bug is a disgraceful affair, like a crime, that requires
- anonimity of the person and his organization ?
-
- Rob J. Nauta
- --
- /-----------------------------------------------\ Never ,==.
- | Rob J. Nauta, UNIX computer security expert. | Apologize, /@ |
- | rob@wzv.win.tue.nl, Phone: +31-40-837549 | Never /_ <
- | Feel free to email me for free advice | Explain. =" `g'
-
-