home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.unix.aix
- Path: sparky!uunet!psinntp!newstand.syr.edu!erc.cat.syr.edu!kcameron
- From: kcameron@erc.cat.syr.edu (Ken Cameron)
- Subject: Should /bin/ecs have SUID root???
- Message-ID: <1993Jan1.190323.11586@newstand.syr.edu>
- Originator: kcameron@erc.cat.syr.edu
- Keywords: security loophole ecs ate
- Organization: Electronic Resource Center, Syracuse
- Date: Fri, 1 Jan 93 19:03:23 EST
- Lines: 18
-
- I discovered that the ecs program (a tool for connecting to IBM InfoNet)
- had the permissions set to -r-sr-s--- root ecs.
- The idea being that you have to add a user to group ecs to
- make it available to them. And I guess that it wanted root so it could
- fiddle with the com ports. HOWEVER, it does have a shell escape and that
- gives the user root access not their own!!! Looks like a hole to me.
- Yet I checked with tcbck and it said it should be suid root. I suspect
- that ate is also effected the same way. And I found that I had both
- /bin/ecs and /usr/bin/ecs but not as links but copies!??
- My current version is 3.2.2 with no other ptf's installed. Anyone with
- clues let me know. Also if this is a hole it should be posted to
- alt.security by an IBM'er if their distrubution is like this.
-
- --
- -ken cameron. SkyDiver: Zoo-602, A-8596, D-11839. Skier.
- Employer: Computer Task Group. /cny UNIX Users Group Director.
- Disclamer: "I said it, when I said it, so what! Now is different!"
- Internet: kcameron@erc.cat.syr.edu
-